DevMan Ransomware: Technical Analysis and Capabilities
DevMan ransomware is a locker that targets Windows, ESXi, and Linux systems. It uses ChaCha20-Poly1305 encryption, fully encrypting files up to 3…
DevMan ransomware is a locker that targets Windows, ESXi, and Linux systems. It uses ChaCha20-Poly1305 encryption, fully encrypting files up to 3…
The operators of the DevMan ransomware-as-a-service (RaaS) scheme maintain a dedicated web platform that offers affiliates the ability to build payloads, oversee…
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
A malware operator left its delivery server exposed, allowing Rapid7 to recover a full toolkit of 1,048 files including lure templates, filename-spoofing…
A critical vulnerability (CVSS 8.8) in Windows WebDAV that allows attackers to hijack the working directory of signed binaries, leading to remote…
A critical vulnerability in 7-Zip, identified as CVE-2026-14266, allows attackers to execute arbitrary code by tricking users into opening a specially crafted…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack dubbed 'SleeperGem' targeting the Ruby ecosystem. Three malicious gems were published to…
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability,…
Zoom Desktop Client for Windows is the primary application for participating in Zoom meetings on Windows PCs. It is affected by CVE-2026-53412.