NadMesh Botnet Targets Exposed AI Services for Cloud Credentials and Kubernetes Tokens
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
SANS ISC handler Brad Duncan documented an ACR Stealer infection traced to a page impersonating Claude AI, reached through malicious Google ads.
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into…
ZeroBAC is an email security company that discovered and analyzed the Forg365 PhaaS operation, providing detailed technical analysis of its capabilities.
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
Lexfo is a French security company that discovered and analyzed three Evilginx phishing operations targeting Microsoft 365, leveraging a misconfigured server to…
Hunt.io is a cybersecurity company that provides threat intelligence and investigation services. In August 2026, Hunt.io disclosed details of Operation CameraSwarm, a…
Binary Defense identified the same malware as BLUERABBIT and tied it to an Iran-nexus group targeting Israeli organizations, citing Google's Threat Intelligence…
Datadog Security Labs has uncovered several overlapping campaigns that leverage dormant GitHub accounts—some created two to five years ago—to systematically enumerate corporate…
Cybersecurity researchers have identified a new ransomware family named GodDamn, which leverages the PoisonX kernel driver to disable endpoint defenses. First observed…