Click here to download all references as Bib-File.•
| 2026-06-09
⋅
ExaTrack
⋅
LotusLite: Believe me I am MustangPanda LOTUSLITE |
| 2026-06-08
⋅
Proofpoint
⋅
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency Overlord RAT |
| 2026-06-08
⋅
StepSecurity
⋅
The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent Shai-Hulud |
| 2026-06-07
⋅
Socket
⋅
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave Shai-Hulud |
| 2026-06-03
⋅
sonatype
⋅
Lazarus Group's Latest: Brandjacking Campaign on npm |
| 2026-06-02
⋅
Qualys
⋅
The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs CL-STA-1020 |
| 2026-06-01
⋅
ExaTrack
⋅
Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026 PixyNetLoader |
| 2026-05-31
⋅
Gridinsoft
⋅
DriveSurge Turns Trusted Websites Into ClickFix Malware Traps DriveSurge |
| 2026-05-31
⋅
Socket
⋅
Famous Chollima Targets PHP Developers Through Compromised Packagist Package JADESNOW |
| 2026-05-28
⋅
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations LegionRelay PhantomRelay |
| 2026-05-28
⋅
WithSecure
⋅
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations GreyVibe |
| 2026-05-27
⋅
Group-IB
⋅
The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament GHOST STADIUM |
| 2026-05-26
⋅
Intrinsec
⋅
Pivoting on a malspam infrastructure delivering JS malware backed by bulletproof networks |
| 2026-05-24
⋅
cocomelonc
⋅
Malware shellcode delivery via signal - part 1. FSK Basics. Simple python script |
| 2026-05-22
⋅
Fox-IT
⋅
RemotePE: The Lazarus RAT that lives in memory DPAPILoader RemotePE |
| 2026-05-22
⋅
Check Point
⋅
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict MiniFast |
| 2026-05-22
⋅
Trend Micro
⋅
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware BeaverTail InvisibleFerret |
| 2026-05-21
⋅
PWC
⋅
Inside Red Lamassu’s JFMBackdoor JFMBackdoor Calypso |
| 2026-05-20
⋅
Hackernoon
⋅
ZeffSec Resurfaces on Telegram, Claims Breach of Gozine2.ir ZeffSec |
| 2026-05-20
⋅
K7 Security
⋅
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading ValleyRAT |