Hackers have built a Windows backdoor that uses Microsoft 365 for all its native command and control communications. Named Antino, the malware turns Outlook messages and OneDrive files into channels for issuing instructions, moving stolen data, and maintaining access...
A fake Zoom installer is tricking Mac users into handing over their login passwords and launching CloudSyncD, a newly identified backdoor.
The malware hides inside an application that looks familiar, using installation instructions and counterfeit prompts to turn routine...
A WordPress backdoor is bringing deleted malware back within seconds, turning routine cleanup into a cycle of reinfection. Called SC, the infection spreads its working parts across website files, the database, and server memory, allowing surviving components to restore...
Hackers are abusing Microsoft Defender Antivirus exclusions to keep malicious files outside routine security scans. Rather than switching protection off completely, attackers can leave antivirus running while creating gaps around malware staging folders and selected file types.
This is an...
Hackers are exploiting a serious flaw in internet-facing Zimbra mail servers with specially crafted emails. The weakness lets an outsider run commands on a vulnerable server without logging in or persuading an employee to open a message.
The activity centers...
2CLoader is a newly identified malware loader that helps attackers place credential-stealing programs on Windows computers.
The loader was first seen in August 2026 and has mainly distributed the Vidar and Remus information stealers, alongside XWorm RAT.
These threats can...
Russian state-linked hackers have expanded a phishing operation that uses a new RedFlick delivery chain to reach more than 100 organizations.
The campaign replaces an obvious malicious attachment with a conversation that looks like ordinary professional correspondence.
The activity was...
PaperPhone is a large headless-browser network built to make automated web requests look like ordinary mobile traffic. It does not rely on a single obvious source.
Instead, it spreads activity across thousands of addresses while repeatedly presenting fabricated phone...
A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an...
Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device.
The phishing emails use meeting invitations,...