Chinese APT Group Deploys Signed Kernel Rootkit to Hide ‘CoolClient’ Backdoor on Government Networks
Researchers have exposed a HoneyMyte campaign that pairs the PlugX loader with a new backdoor called CoolClient, concealed by a digitally signed kernel rootkit driver. The malware has...
‘Bring Your Own EDR’ Trick Turns SentinelOne Into a Bodyguard for Malware
DEF CON 34 research shows how trusted SentinelOne components could be abused to dump memory from Windows' most protected processes, ultimately shielding malicious payloads behind the endpoint agent's...
Lazarus Group Weaponizes Windows Kernel Zero-Day to Deploy Next-Generation FudModule Rootkit
Check Point Research has caught North Korea's Lazarus group exploiting a previously unknown Windows kernel flaw, CVE-2026-68820, to plant an upgraded FudModule rootkit on defense and aerospace targets....
Researchers Show How Malware Can Hijack Windows Hello Keys to Slip Into Microsoft Entra ID
New research demonstrates that malware running inside an active, unlocked Windows session can abuse Windows Hello for Business cryptographic keys to authenticate to Microsoft Entra ID, without ever...
ChainDrop Worm Spreads Through 400+ npm Packages, Raiding Developer and Cloud Credentials
A self-propagating worm dubbed ChainDrop has infected more than 400 npm packages by hijacking trusted publishing accounts, quietly harvesting npm, GitHub, cloud, and SSH credentials from developer machines...
New Vanta Stealer Malware Raids Browsers, Crypto Wallets and Gaming Accounts in a Single Sweep
A newly documented information stealer called Vanta Stealer goes well beyond saved browser passwords, harvesting cookies, payment data, Discord tokens, gaming accounts and cryptocurrency wallet files in one...
SilverFox Malware Deploys New Kernel Drivers to Blind Antivirus Before Installing ValleyRAT
Researchers at CATO Networks have caught the SilverFox threat group hiding behind trusted PDF software while quietly loading vulnerable, signed kernel drivers to knock out endpoint protection. The...
Fake VS Code Extensions Quietly Siphoned Git and CI Secrets From Developers
Seventy-seven counterfeit Open VSX extensions impersonated legitimate developer tools and quietly phoned home to a single attacker-controlled domain. Nineteen of them went further, harvesting Git repository details and...