Daxin Rootkit Resurfaces in Taiwan Alongside Novel Stupig Pre-Logon Backdoor
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm,…
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm,…
Stupig (a.dll or kbdus1.dll) is a DLL backdoor that achieves persistence by registering as a keyboard-layout provider, causing win32k.sys to load it…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
The Quarry is a PhaaS kit developed by a lone operator named RockyBelling, used for credential theft via emails mimicking IRS, SSA,…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
A Rust-based infostealer was distributed through a compromised version of the jscrambler npm package. It steals cloud credentials, cryptocurrency wallets, password manager…
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…
Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…