Iranian state-sponsored hackers affiliated with the Ministry of Intelligence and Security (MOIS) have been using a previously undocumented modular command-and-control (C2) framework…
An IP address from ProtonVPN service (159.26.98[.]241) was observed in the initial reconnaissance phase of the attempted exploitation of CVE-2026-20896, though no…
CountLoader is a malware family delivered via DOUBLECUP, with Windows and macOS variants. It establishes persistence via scheduled tasks, audits browser extensions…
Censys, an internet scanning service, is being leveraged by threat actors to identify internet-exposed PLCs running outdated software. This reconnaissance method is…
A new malware family named AryStinger, discovered by QiAnXin's XLab, has infected at least 4,300 legacy routers to create a distributed reconnaissance…
AryStinger is a botnet that enlists older, vulnerable home routers into a network for distributed reconnaissance and proxying, highlighting the growing threat…