// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
malware

HollowGraph: APT Malware Turns M365 Calendars into Covert C2 Channel

HollowGraph exploits the Microsoft Graph API to transform compromised account calendars into bidirectional command-and-control channel…

Aug 22, 2026views - 1.1k

malware

SynkLoader: The 'Kitchen Sink' Malware Attacking via Microsoft Teams

Expel researchers have uncovered SynkLoader, a modular, multi-language malware family that uses Microsoft Teams phishing to breach cor…

Aug 21, 2026views - 1k

malware

Android Malware in Car Head Units: Vehicles Become Gig-Economy Nodes

Kaspersky discovered in June 2026 a new Android malware family that infects DoFun automotive head units through their built-in TWCore…

Aug 21, 2026views - 502

malware

Lumma Stealer Hides in Pirated 'The Odyssey' Downloads: The Hidden Extension Trick

Cybercriminals are distributing Lumma Stealer via Windows executables disguised as pirated copies of The Odyssey (2026) on torrent tra…

Aug 18, 2026views - 1.1k

malware

Mustang Panda Arms CoolClient with Signed Rootkit: EDR in the Kernel Crosshairs

HoneyMyte deploys msagent.sys, a kernel-mode rootkit driver signed with an expired 2013 certificate. It hides processes, files, and C2…

Aug 17, 2026views - 1.1k

malware

AmnesiaStealer: The macOS Malware That Hijacks Victim Browser Sessions in Real Time

Jamf Threat Labs has documented AmnesiaStealer, a Rust-based macOS infostealer that clones the victim's Chromium profile, launches it…

Aug 17, 2026views - 1.1k

malware

WindRelay Turns Android Phones into NFC Relays to Drain Contactless Cards

Group-IB discovered WindRelay, Android malware that captures and relays contactless payment card NFC data in real time during social-e…

Aug 13, 2026views - 1.2k

malware

Pirated 'The Odyssey' Downloads Hide Lumma Stealer: Windows Users Tricked by Fake Video Files

Cybercriminals are recycling a proven attack pattern to distribute Lumma Stealer through fake pirated copies of Christopher Nolan's Th…

Aug 09, 2026views - 1.2k

malware

VoidLink: The Cloud-Native Malware Turning Linux into an Attack SaaS

Check Point Research discovered VoidLink in December 2025, a cloud-native Linux malware framework written in Zig with 30-plus plugins,…

Aug 08, 2026views - 1.3k

malware

QLNX: The Linux RAT Targeting Software Supply Chain Keys

Trend Micro discovered QLNX, a previously undocumented Linux RAT that combines a dual-tier rootkit, PAM backdoor, and P2P network to s…

Aug 04, 2026views - 1.2k

malware

SourTrade: The Browser Becomes an In-Memory Malware Factory

The SourTrade malvertising campaign assembles malware directly in the victim's browser memory using legitimate web APIs. The technique…

Aug 02, 2026views - 1.1k

malwareCRITICAL

BRICKSTORM: Chinese Backdoor Targets US and Canadian Critical Infrastructure

CISA, NSA, and the Canadian Centre for Cyber Security disclosed BRICKSTORM, Chinese state-sponsored malware with 17-month persistence…

Jul 28, 2026views - 1.4k