malware

Pierluigi Paganini August 12, 2026
Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum

Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on February 3, 2026, while hunting threats following public disclosures of the botnet’s earlier activity. The new version substantially upgrades the DDoS capabilities and command infrastructure of a botnet that has […]

Pierluigi Paganini August 09, 2026
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums   DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster   Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba […]

Pierluigi Paganini August 09, 2026
Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild, […]

Pierluigi Paganini August 06, 2026
Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records

Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of customer records, and extorted multiple victims for millions of dollars. “Connor Riley Moucka, 26, […]

Pierluigi Paganini August 05, 2026
SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access

SMOKE#SCREEN uses fake Zoom updates to install ScreenConnect RMM, giving attackers persistent remote access while bypassing defenses. Securonix Threat Research has been tracking an active multi-wave campaign they’ve named SMOKE#SCREEN, in which unknown attackers use rotating social engineering lures, fake Zoom updates, Adobe software notices, business document reviews, system maintenance utilities, to silently install ConnectWise […]

Pierluigi Paganini August 04, 2026
INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit

INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since […]

Pierluigi Paganini August 03, 2026
River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted

River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit parts of its server environment in June. The breach began on June […]

Pierluigi Paganini August 02, 2026
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Modular Tools  Inside a DPRK BlueNoroff ClickFix Kit SourTrade: Browser-Assembled Malware Delivered Through Malvertising   MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions   Unpacking “Cruciferra”: An Analysis of a […]

Pierluigi Paganini August 02, 2026
Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens Adobe fixed a maximum-severity vulnerability flaw in […]

Pierluigi Paganini July 31, 2026
SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign

SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL documented a new SilverFox campaign targeting a Japanese industrial manufacturer. The attack chain adds two previously undocumented DLL-sideloading hosts, two kernel drivers not previously associated with SilverFox, and a dual-layer recovery architecture that keeps ValleyRAT running […]