SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Pierluigi Paganini September 20, 2026

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

Gray Rabbits and the Tale of a One-Click Backdoor  

Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit

Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service  

Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows  

The banana stand: brokering and managing infections across Asia using MQTT 

Iranian cyber targeting of dissidents, activists and journalists

SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia

Beware the SparroWock: The backdoor that bites, the commands that catch

Brevo supply chain attack hits 100k+ sites with WordPress backdoors and Clickfix malware 

Skill Poisioning turning AI agents into malware droppers – warns China’s National CERT  

RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts  

Brevo supply chain attack hits 100k+ sites with WordPress backdoors and Clickfix malware 

The extension you never installed: KREMLIN forges Chrome’s own integrity checks to steal banking sessions 

Delphi Scanner: efficient and interpretable static malware detection via API sequence modeling

ALIBI: Adversarial Legitimacy Injection in Binary Input against LLM Malware Analyzers

Metamorphic Malware Detection via Graph-Augmented Neural Semantics and Adversarial Hardening: A Comprehensive Framework

Uncertainty-Aware Zero-Day Botnet Detection for IoT Networks with Real-World Edge Deployment on Resource-Constrained Hardware

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment