Security news
Latest security news
Tue, 18 Aug 2026
- Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional downloaders and
Check Point ResearchWordPress
Mon, 17 Aug 2026
- Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered prompts, shell history, and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution. When one model began resisting parts of that workflow, the operator switched providers and attempted to bypass the next model's safety controls with a custom jailbreak prompt. Together, these artifacts provide an unusual view into how AI was integrated into the development of an active phishing operation rather than simply being used to generate isolated snippets of code. We track this activity as Operation ASTERIX, named after the Asterisk open-source telephony platform recovered on the serve
Rapid7 Blog - Infostealers Harvest 1.7 Billion Credentials in Six Months
Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026
Infosecurity Magazine
Fri, 14 Aug 2026
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies
Infosecurity MagazineLinux - Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
AmnesiaStealer contains novel functions, including the attackers gaining remote control over the victim’s browser to steal cookie data
Infosecurity Magazine - APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
SecurelistWindows
Thu, 13 Aug 2026
- The Model Is the Malware | What Four Agentic Intrusions Tell Defenders
OpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn't matter, and that changes the playbook for investigating intrusions.
SentinelLabs
Wed, 12 Aug 2026
- WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call
Infosecurity Magazine - Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Infosecurity MagazineWindows, Exchange
About this news
- 1,259
- Stories
- 31
- Added in the last 24 hours
- 16
- Critical in the last 7 days
- 4
- Reported by several outlets