BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have uncovered a supply chain attack targeting WordPress plugin vendor BdThemes, leading to the temporary suspension of several plugins from…
Cybersecurity researchers have uncovered a supply chain attack targeting WordPress plugin vendor BdThemes, leading to the temporary suspension of several plugins from…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
Cybersecurity researchers at Blackpoint Cyber have uncovered a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as…
Matryoshka is a Rust-based backdoor family deployed in attacks on law firms. It comes in two variants: one uses HTTP-based communication for…
Cybersecurity researchers at Zscaler ThreatLabz have uncovered a malicious campaign targeting government entities in the Middle East, attributed to an East Asian…
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are…
A command-and-control listener found running on the attacker's staging server alongside the Hermes agent tooling.
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
Cybersecurity researchers have uncovered a new modular malware called TELEPUZ that has been spreading since late April 2026 through websites infected with…
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm,…