// 1 ZERO-DAY · 3 CVE · 2 EXPLOIT IN THE LAST 24H
malware

Node.js Turns Trojan Horse: Signed Runtime Hides Targeted Malware

Symantec uncovers threat actors abusing node.exe — a legitimate, signed binary — to deliver malicious payloads against government and…

Sep 03, 2026views - 878

CYBERSEC

GitHub Reveals the True Cost of Ingesting Threat Intelligence at Scale

The Dependabot lead details how ingesting 18 malicious packages per day across 30 million repositories demanded more validation engine…

Sep 03, 2026views - 1k

CYBERSEC

Silver Fox Pushes Fake Installers That Kill Windows Update and Weaken Defender

Microsoft exposes a campaign by the Chinese Silver Fox cluster using pixel-perfect clone sites of popular software to deliver installe…

Sep 02, 2026views - 1.1k

ransomware

VantaCore: Pro-Ukraine Group Relaunches with Custom Ransomware Targeting Russia

VantaCore, a rebrand of the pro-Ukraine Thor group, is hitting Russian organizations with a proprietary arsenal of ransomware and remo…

Sep 02, 2026views - 1.2k

CYBERSEC

FulcrumSec Steals 86 GB of MAG Data: API Keys Were Hardcoded in Client-Side JavaScript

The FulcrumSec data extortion group claimed responsibility for the Manchester Airports Group breach, publishing ~86 GB of data. Access…

Sep 02, 2026views - 1.1k

CYBERSEC

Russian Extradited from Cyprus: Charged in Malware Campaign Targeting 80,000 Freelancers

Searzhudin Aktulaev was extradited to the U.S. for a 2016–2017 campaign that used malicious Excel files to infect freelancers. The mac…

Sep 02, 2026views - 993

CYBERSEC

Sality Disrupted: The Takedown That Turned Its P2P Network Into a Trap

On August 31, 2026, international authorities disrupted the Sality botnet by weaponizing its own peer-to-peer protocol. The malware re…

Sep 02, 2026views - 1.1k

malware

Guildma's Brazilian Geofencing: Malware That Only Shows Up for Real Targets

A SANS researcher documented Guildma (Astaroth), a Latin American banking trojan active since 2017, delivering its payload exclusively…

Sep 02, 2026views - 1.1k

CYBERSECZERO-DAY

SonicWall SMA1000: Active Zero-Days Enable Lateral Movement Without VPN

Two zero-day vulnerabilities in SonicWall SMA1000 allow unauthenticated RCE and lateral movement to Active Directory without VPN tunne…

Sep 02, 2026views - 1k

CYBERSECEXPLOIT

HardBreacher Breaches the Kaspersky Perimeter: When the Protector Becomes the Gatekeeper

Nightmare Eclipse releases HardBreacher, a proof-of-concept exploit that turns the Kaspersky UI process into a privilege escalation ve…

Aug 31, 2026views - 1.1k

malware

Check Point Unveils Pipeline That Reads JSCeal Without Executing It

Check Point Research has released an open-source toolkit for statically deobfuscating JSCeal payloads on V8 bytecode. The pipeline suc…

Aug 31, 2026views - 1.1k

malwareEXPLOIT

ValleyRAT Backdoor Hides in Signed Adware, Bypasses AV via DLL Sideloading

The Silver Fox group is distributing the ValleyRAT backdoor — also known as Winos 4.0 — packaged inside QN Wallpaper, a legitimate, di…

Aug 31, 2026views - 1.1k