Security news

Latest security news

175 of 1,259 storiesTopic: MalwareClear all

Tue, 18 Aug 2026

  1. Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

    Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional downloaders and

    Check Point ResearchWordPress

Mon, 17 Aug 2026

  1. Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

    Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered prompts, shell history, and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution. When one model began resisting parts of that workflow, the operator switched providers and attempted to bypass the next model's safety controls with a custom jailbreak prompt. Together, these artifacts provide an unusual view into how AI was integrated into the development of an active phishing operation rather than simply being used to generate isolated snippets of code. We track this activity as Operation ASTERIX, named after the Asterisk open-source telephony platform recovered on the serve

    Rapid7 Blog
  2. Infostealers Harvest 1.7 Billion Credentials in Six Months

    Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026

    Infosecurity Magazine

Fri, 14 Aug 2026

  1. New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

    Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies

    Infosecurity MagazineLinux
  2. Novel macOS Infostealer AmnesiaStealer Spread via ClickFix

    AmnesiaStealer contains novel functions, including the attackers gaining remote control over the victim’s browser to steal cookie data

    Infosecurity Magazine
  3. APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

    Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

    SecurelistWindows

Thu, 13 Aug 2026

  1. The Model Is the Malware | What Four Agentic Intrusions Tell Defenders

    OpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn't matter, and that changes the playbook for investigating intrusions.

    SentinelLabs

Wed, 12 Aug 2026

  1. WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam

    New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call

    Infosecurity Magazine
  2. Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

    Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit

    Infosecurity MagazineWindows, Exchange

About this news

1,259
Stories
31
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets