NadMesh Botnet Targets Exposed AI Services for Cloud Credentials and Kubernetes Tokens
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
TookPS is a PowerShell downloader used as the initial payload for OkoBot. It has been active since March 2025, delivered via fake…
Cybersecurity researchers at Blackpoint Cyber have uncovered a previously undocumented modular malware framework codenamed Avalon, which is distributed via a multi-stage phishing…
Storm-2603 configured SSH connections through Visual Studio Code as part of multiple remote access channels during attacks.
Threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow (CVSS 9.3), to deploy a Monero cryptocurrency…
A public proof-of-concept (PoC) has been released for CVE-2026-55200, a critical vulnerability in the libssh2 client-side SSH library. The flaw, with a…
A critical client-side SSH vulnerability in libssh2, CVE-2026-55200, has a public proof-of-concept exploit.
OpenSSH is a suite of secure networking utilities that was backdoored by Velvet Ant to log credentials and commands, with a hidden…
Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a…
OpenSSH Server was installed on a Windows workstation by the attacker to enable key-based SSH access and reverse tunnels, providing a backdoor…