Latest news

Trojanized KeePass campaign: novel loader and credential theft in ransomware operations
Malware

Trojanized KeePass campaign: novel loader and credential theft in ransomware operations

14 May 2025 securebulletin.com

A recent investigation by WithSecure’s Threat Intelligence team has uncovered a sophisticated malware campaign leveraging a trojanized version of the...
Sophisticated npm malware campaign exploits Cross-Ecosystem typosquatting
Malware

Sophisticated npm malware campaign exploits Cross-Ecosystem typosquatting

3 May 2025 securebulletin.com

A coordinated malware operation targeting npm employs cross-ecosystem typosquatting to mimic popular libraries from Python, Java, C++, and .NET ecosystems....
SuperCard X: exposing a MaaS for NFC Relay fraud operation
Malware

SuperCard X: exposing a MaaS for NFC Relay fraud operation

20 April 2025 securebulletin.com

The Cleafy Threat Intelligence team has uncovered SuperCard X, a sophisticated Android malware campaign leveraging NFC-relay attacks to authorize fraudulent...
Malicious NPM packages targeting PayPal users: a recap analysis
Malware

Malicious NPM packages targeting PayPal users: a recap analysis

12 April 2025 securebulletin.com

FortiGuard Labs recently uncovered a series of malicious NPM packages designed to steal sensitive information from compromised systems. These packages,...
Malicious VSCode extensions: a growing threat to developers
Malware

Malicious VSCode extensions: a growing threat to developers

7 April 2025 securebulletin.com

The Visual Studio Code (VSCode) Marketplace has recently become a target for sophisticated cyberattacks, with malicious extensions infiltrating development environments...
Stealth malware strikes WordPress via MU-Plugins: a technical deep dive
Malware

Stealth malware strikes WordPress via MU-Plugins: a technical deep dive

30 March 2025 securebulletin.com

The Sucuri research team has recently uncovered a concerning trend: threat actors are increasingly leveraging the WordPress mu-plugins directory to...
New breed of Android malware leverages .NET MAUI to slip past defenses
Malware

New breed of Android malware leverages .NET MAUI to slip past defenses

25 March 2025 securebulletin.com

Exploiting cross-platform development frameworks to deliver insidious malware. A recent report from McAfee highlights the emergence of Android malware campaigns...
MassJacker malware targets cryptocurrency of piracy users
Malware

MassJacker malware targets cryptocurrency of piracy users

14 March 2025 securebulletin.com

A new and sophisticated malware campaign, known as MassJacker, has been uncovered by cybersecurity researchers at CyberArk. This malware targets...
The Ballista Botnet: a new IoT threat with italian roots
Malware

The Ballista Botnet: a new IoT threat with italian roots

11 March 2025 securebulletin.com

Cato Networks has uncovered a sophisticated IoT botnet, dubbed Ballista, targeting TP-Link Archer routers by exploiting a two-year-old vulnerability (CVE-2023-1389)....
Russia-Aligned actors intensify targeting of Signal Messenger
Malware

Russia-Aligned actors intensify targeting of Signal Messenger

19 February 2025 dark6

Recent reporting from Google’s Threat Intelligence Group (GTIG) highlights a surge in activity from Russian state-aligned threat actors targeting Signal...
Oh Ship! Steam game “PirateFi” caught red-handed dropping password-stealing malware
Malware

Oh Ship! Steam game “PirateFi” caught red-handed dropping password-stealing malware

16 February 2025 dark6

Ahoy, gamers! Hope you weren’t sailing the high seas of Steam with a recently released free-to-play game called PirateFi. Turns...
Fake wedding invitations to spread Android Malware in Southeast Asia
Malware

Fake wedding invitations to spread Android Malware in Southeast Asia

1 February 2025 securebulletin.com

Since mid-2024, a new malware campaign targeting Android users has emerged, identified as the Tria stealer. This malware exploits wedding...