Click here to download all references as Bib-File.•
| 2026-07-29
⋅
SafeDep
⋅
Joyfill npm Packages Compromised with Blockchain C2 Loader JADESNOW |
| 2026-07-28
⋅
Socket
⋅
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan JADESNOW |
| 2026-07-15
⋅
Symantec
⋅
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor Daxin |
| 2026-07-07
⋅
Proofpoint
⋅
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation IceCube |
| 2026-07-02
⋅
FBI
⋅
Cyber Criminal Group TeamPCP Shai-Hulud TeamPCP |
| 2026-06-25
⋅
Microsoft Security
⋅
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access TonRAT |
| 2026-06-17
⋅
Microsoft
⋅
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet |
| 2026-06-10
⋅
TEAMT5
⋅
CVE-2026-34197:Apache ActiveMQ SoxAgent SLIME88 |
| 2026-06-09
⋅
Zscaler
⋅
Technical Analysis of MLTBackdoor MLTBackdoor |
| 2026-06-08
⋅
SYGNIA
⋅
Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected |
| 2026-06-04
⋅
RESIDENT.NGO
⋅
Case Study — UNC1151 Gmail Phishing (“Suspicious account activity”) Targeting Belarusian Pro-Democracy Politician, May 2026 |
| 2026-06-03
⋅
Proofpoint
⋅
TA4922: The Suspected Chinese Crime Group is Going Global Atlas RAT RomulusLoader SilentRunLoader TA4922 |
| 2026-06-03
⋅
sonatype
⋅
Lazarus Group's Latest: Brandjacking Campaign on npm |
| 2026-05-31
⋅
Gridinsoft
⋅
DriveSurge Turns Trusted Websites Into ClickFix Malware Traps DriveSurge |
| 2026-05-28
⋅
eSentire
⋅
Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT |
| 2026-05-20
⋅
K7 Security
⋅
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading ValleyRAT |
| 2026-05-18
⋅
Microsoft
⋅
How Storm-2949 turned a compromised identity into a cloud-wide breach Storm-2949 |
| 2026-05-16
⋅
Symantec
⋅
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations fast16 |
| 2026-05-13
⋅
Rapid7
⋅
When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise ModeloRAT |
| 2026-05-11
⋅
Qianxin
⋅
Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment Mr_Rot13 |