Rust Infostealer Targets Developer Secrets via Compromised npm Package
A Rust-based infostealer was distributed through a compromised version of the jscrambler npm package. It steals cloud credentials, cryptocurrency wallets, password manager…
A Rust-based infostealer was distributed through a compromised version of the jscrambler npm package. It steals cloud credentials, cryptocurrency wallets, password manager…
QuimaRAT is a Java-based remote access trojan (RAT) advertised under a malware-as-a-service (MaaS) model, capable of targeting Windows, Linux, and macOS. It…
Cybersecurity researchers at LevelBlue have identified a new Java-based remote access trojan (RAT) named QuimaRAT, which is capable of targeting Windows, Linux,…
CountLoader is a malware family delivered via DOUBLECUP, with Windows and macOS variants. It establishes persistence via scheduled tasks, audits browser extensions…
Threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow (CVSS 9.3), to deploy a Monero cryptocurrency…
Yuze is an open-source SOCKS5 proxy tool that has been employed by CL-STA-1062 to route traffic and maintain persistence in targeted environments.
Miasma is a multi-stage botnet loader identified in compromised AsyncAPI npm packages. It features a tasking framework with 744 modules, supporting six…
A now-patched flaw in WinRAR (CVE-2025-8088) was weaponized by Gamaredon to place malicious HTA downloaders into the Windows Startup folder, enabling automatic…
Sygnia, tracking the China-nexus group as Velvet Ant, discovered that the group backdoored Linux PAM and OpenSSH components to maintain persistent access…
Velvet Ant, tracked by Sygnia, is a China-nexus threat actor known for targeting infrastructure components like F5 BIG-IP, Cisco NX-OS, and Linux…