Stealth Linux Rootkit Hides Fileless Web Shells Inside F5 BIG-IP Memory
Researchers have uncovered a Linux rootkit that alters PHP code only in memory on compromised F5 BIG-IP APM appliances. Its fileless web shell, local socket backdoor and upgrade...
Mathspace Breach Exposes Data of More Than One Million Users
Mathspace says attackers exploited a maximum-severity Metabase flaw and downloaded records belonging to 1,079,819 users. A missed vulnerability alert and incomplete post-patch checks allowed the intrusion to remain...
Phishing Campaign Chains Google Services to Conceal Credential Theft
A phishing operation is routing victims through legitimate Google services before sending them to personalized credential traps or unauthorized ScreenConnect installers. The technique weakens domain-reputation defenses and hides...
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent...
North Korean Hackers Hide ‘Ted’ Backdoor Inside Trojanized HAProxy to Spy on South Korean Firms
Rapid7 researchers have uncovered a DPRK-linked Linux intrusion toolkit — built around a modified HAProxy binary dubbed Ted and a companion remote access tool called CurlRAT — that...
Roundcube Patches a Dozen Flaws, Including a Zero-Click Webmail XSS and an IPv6-Based SSRF Bypass
The Roundcube team has shipped versions 1.6.19 and 1.7.4 to close twelve security holes, headlined by a stored cross-site scripting bug that fires the moment a crafted email...
Fake ‘Lithium’ Minecraft Optimization Mod Hides Myth Stealer RAT Behind 12 Working Features
A trojanized Minecraft performance mod posing as the popular Lithium optimization project is quietly installing Myth Stealer, an information-stealing remote access tool that harvests browser credentials, session cookies,...
North Korea-Linked Hackers Hide OtterCookie Malware Inside 14 Fake Mac Apps
Researchers have identified fourteen trojanized macOS installers impersonating popular utilities like The Unarchiver and Sketch, all delivering the OtterCookie credential-stealing malware. The campaign, tied to North Korea's long-running...