Malware Newsletter
Gray Rabbits and the Tale of a One-Click Backdoor
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit
Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
The banana stand: brokering and managing infections across Asia using MQTT
Iranian cyber targeting of dissidents, activists and journalists
Beware the SparroWock: The backdoor that bites, the commands that catch
Brevo supply chain attack hits 100k+ sites with WordPress backdoors and Clickfix malware
Skill Poisioning turning AI agents into malware droppers – warns China’s National CERT
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
Brevo supply chain attack hits 100k+ sites with WordPress backdoors and Clickfix malware
Delphi Scanner: efficient and interpretable static malware detection via API sequence modeling
ALIBI: Adversarial Legitimacy Injection in Binary Input against LLM Malware Analyzers
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)