INC Ransomware Exploits SonicWall SMA 1000 Zero-Days in Widespread Attacks
INC Ransomware has emerged as the dominant threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN…
INC Ransomware has emerged as the dominant threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN…
GHOSTBLADE is an information-stealing malware deployed on iOS devices via the DarkSword exploit kit. It delivers keychain, iCloud, and Wi-Fi credential-dumping modules…
A Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the…
Go-based remote access trojan delivered via fake updates in the CaptiveCrunch campaign. It captures screenshots, steals credentials, and provides remote shell access.
ChocoShell, also known as CHERRYPIE, is a PowerShell-based infostealer delivered via ClickFix lures. It steals browser session cookies, saved passwords, Microsoft 365…
Russian threat actors linked to the exploitation of a Zimbra vulnerability have been observed exploiting CVE-2026-42897, a cross-site scripting (XSS) flaw in…
Ruby on Rails has released fixes for a critical Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5), that could allow unauthenticated attackers to read…
Security researchers have identified traces of the Flying Eagle Android remote access trojan (RAT) framework on 170 internet servers, as its source…
Flying Eagle is an Android remote access trojan (RAT) framework that supports payment-password and keystroke capture, screen recording, camera access, and phishing…
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…