New ClickFix Variants Exploit Windows Tools to Spread Malware
Over the last year, cybercriminals have increasingly used a trick called ClickFix to get people to run…
continue reading..
Critical Flaw in Claude Code Exposes Developers to Remote Code Execution and API Key Theft (CVE-2025-59536)
Cybersecurity researchers from have uncovered serious vulnerabilities in Anthropic’s Claude Code — the AI-powered coding assistant —…
continue reading..
Advanced PlugX Variant Uses DLL Side-Loading and In-Memory Execution in Recent Campaign
In January 2026, a new variant of the PlugX malware was used in targeted attacks. Based on…
continue reading..
Vshell: Chinese-Language C2 Framework Emerges as Cobalt Strike Alternative in Active Threat Campaigns
Vshell is a remote administration tool written in Go that offers comprehensive post-compromise features such as network…
continue reading..
Belarusian KGB Deploys “ResidentBat” Android Spyware in Targeted Physical Device Seizures
A newly documented Android spyware family called ResidentBat has been attributed to Belarus’s State Security Committee (KGB),…
continue reading..
Threat Actor UAT-8616 Targets Enterprise Networks via SD-WAN Flaw
Cisco Talos reports that a highly sophisticated cyber threat actor, tracked as UAT-8616, is actively exploiting a…
continue reading..
“Oblivion” Android RAT Sold for $300 Bypasses Major Phone Security, Targets Devices Running Android 8–16
A powerful new Android Remote Access Trojan (RAT) called Oblivion has recently appeared, and cybersecurity researchers at…
continue reading..
Microsoft Uncovers Developer-Targeted Campaign Using Malicious Next.js Repositories for C2 Operations
Microsoft Defender Experts and the Microsoft Defender Security Research Team have uncovered a coordinated cyber campaign that…
continue reading..
Agent Tesla Campaign Uses File-Hosting Services and In-Memory Loaders to Evade Detection
Agent Tesla continues to be a dominant threat in the cyber landscape, due to its adaptability, simplicity…
continue reading..
