Security news

Latest security news

176 of 1,263 storiesTopic: MalwareClear all

Wed, 2 Sept 2026

  1. Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

    Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors,

    Check Point ResearchLinux

Tue, 1 Sept 2026

  1. Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

    Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

    Securelist

Mon, 31 Aug 2026

  1. Anthropic Users Hit by Infostealer Attacks, Session Thefts

    A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.

    Dark Reading
  2. Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

    Next-level ClickFix wave sets off multi-stage attack chain

    The Register
  3. Anthropic cracks down on hijacked user accounts mining AI tokens

    Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage

    The Register
  4. Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

    Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early

    Check Point Research
  5. Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

    Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

    Unit 42Microsoft
  6. ValleyRAT masquerading as adware

    Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.

    Securelist

About this news

1,263
Stories
35
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets