Thursday, October 1, 2026
Follow on LinkedIn

Threats

Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365

Hackers have built a Windows backdoor that uses Microsoft 365 for all its native command and control communications. Named Antino, the malware turns Outlook messages and OneDrive files into channels for issuing instructions, moving stolen data, and maintaining access...

Fake Zoom Installer Tricks Mac Users Into Installing New CloudSyncD Backdoor

A fake Zoom installer is tricking Mac users into handing over their login passwords and launching CloudSyncD, a newly identified backdoor. The malware hides inside an application that looks familiar, using installation instructions and counterfeit prompts to turn routine...

WordPress Malware Comes Back After Removal Using a Self-Healing Backdoor

A WordPress backdoor is bringing deleted malware back within seconds, turning routine cleanup into a cycle of reinfection. Called SC, the infection spreads its working parts across website files, the database, and server memory, allowing surviving components to restore...

Hackers Abuse Microsoft Defender Exclusions to Hide Malware From Antivirus Scans

Hackers are abusing Microsoft Defender Antivirus exclusions to keep malicious files outside routine security scans. Rather than switching protection off completely, attackers can leave antivirus running while creating gaps around malware staging folders and selected file types. This is an...

Hackers Exploit Zimbra Mail Servers With Crafted Emails to Gain Remote Access

Hackers are exploiting a serious flaw in internet-facing Zimbra mail servers with specially crafted emails. The weakness lets an outsider run commands on a vulnerable server without logging in or persuading an employee to open a message. The activity centers...

New 2CLoader Malware Evades Security Tools to Deploy Vidar and Remus Stealers

2CLoader is a newly identified malware loader that helps attackers place credential-stealing programs on Windows computers. The loader was first seen in August 2026 and has mainly distributed the Vidar and Remus information stealers, alongside XWorm RAT. These threats can...

Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack

Russian state-linked hackers have expanded a phishing operation that uses a new RedFlick delivery chain to reach more than 100 organizations. The campaign replaces an obvious malicious attachment with a conversation that looks like ordinary professional correspondence. The activity was...

PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries

PaperPhone is a large headless-browser network built to make automated web requests look like ordinary mobile traffic. It does not rely on a single obvious source. Instead, it spreads activity across thousands of addresses while repeatedly presenting fabricated phone...

Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches

A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an...

Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs

Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations,...

Latest News

Latest News