Click here to download all references as Bib-File.•
| 2026-07-23
⋅
Proofpoint
⋅
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 SpyPress |
| 2026-07-23
⋅
Proofpoint
⋅
TA488 Targets Zimbra Mailservers with Half-Click Exploits ZimReaper |
| 2026-07-23
⋅
Group-IB
⋅
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake AdaptixC2 reGeorg |
| 2026-07-22
⋅
Prophet Security
⋅
EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain |
| 2026-07-22
⋅
Huntress Labs
⋅
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT SectopRAT |
| 2026-07-22
⋅
bluecyber
⋅
Beyond the Archive: CVE-2025-8088 Stealer Targeting Ukraine GIFTEDCROOK |
| 2026-07-21
⋅
kienmanowar Blog
⋅
[QuickNote] Mustang Panda ToneShell (APT S1239) Beacon Shellcode – RE Analysis TONESHELL |
| 2026-07-21
⋅
DTEX
⋅
From Payroll to Pyongyang: The DPRK IT Worker Money Trail |
| 2026-07-20
⋅
Medium Ireneusz Tarnowski
⋅
INC Ransom: Infrastructure Analysis, Operational Tradecraft, and Detection Opportunities INC INC |
| 2026-07-17
⋅
Volexity
⋅
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation Behinder UTA0533 |
| 2026-07-17
⋅
OpenSourceMalware
⋅
ChainVeil and ViteVenom are DPRK’s PolinRider Campaign JADESNOW |
| 2026-07-17
⋅
Elastic
⋅
New North Korean campaign uses fake coding interviews to steal developer credentials OtterCookie |
| 2026-07-16
⋅
Cisco Talos
⋅
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign CASTLESTEALER Remcos UAT-11795 |
| 2026-07-16
⋅
Hacking But Legal
⋅
North Korea Is Hiring StoatWaffle |
| 2026-07-16
⋅
Microsoft Security
⋅
ACR Stealer: Two observed intrusion chains amid increased threat activity ACR Stealer |
| 2026-07-16
⋅
Elastic
⋅
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains TELEPUZ |
| 2026-07-15
⋅
Zscaler
⋅
ClaudeFix: Shared Claude Chats Meet ClickFix MacSync |
| 2026-07-15
⋅
Symantec
⋅
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor Daxin |
| 2026-07-14
⋅
Checkmarx
⋅
Sequel to ChainVeil npm Malware Targets Vite Ecosystem JADESNOW |
| 2026-07-14
⋅
Ctrl-Alt-Intel
⋅
Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links |