14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers at Trend Micro's TrendAI have uncovered a set of 14 trojanized npm packages that masquerade as legitimate calendar and streak…
Cybersecurity researchers at Trend Micro's TrendAI have uncovered a set of 14 trojanized npm packages that masquerade as legitimate calendar and streak…
The China-linked threat actor known as Jewelbug has been observed conducting cyber espionage against governments and militaries while simultaneously running a cryptocurrency…
Earth Alux is a threat cluster identified by Trend Micro that overlaps with Jewelbug. It is linked to espionage operations and uses…
A new analysis by Oligo Security has uncovered that the threat actor known as TeamPCP has been active in the cybercrime scene…
Fortinet FortiGuard Labs has disclosed a long-standing supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Cybersecurity researchers have uncovered a large-scale campaign that weaponizes compromised GitHub repositories to target cPanel and WebHost Manager (WHM) instances. The activity…
A solo Russian-speaking threat actor known as "bandcampro" has been observed using Google's open-source Gemini CLI AI to control a botnet of…
A critical vulnerability in 7-Zip, identified as CVE-2026-14266, allows attackers to execute arbitrary code by tricking users into opening a specially crafted…
ZDI is a vulnerability disclosure program run by Trend Micro that rewards researchers for responsibly disclosing vulnerabilities. It provided independent counts and…