// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
malware

OctagonPanel Spyware Hides Behind Fake Bahrain Civil Defense Alert App

A counterfeit "BH Alert" app impersonating Bahrain's civil defense system delivers the OctagonPanel surveillance malware via a four-st…

Jul 27, 2026views - 1.1k

malware

RedHook RAT: Android Malware Gains Shell Access Without Root or PC

The RedHook trojan upgrades its arsenal by abusing Wireless ADB, Shizuku, and Accessibility Service to obtain shell privileges on non-…

Jul 12, 2026views - 1.5k

malware

Operation Muck and Load: 222 GitHub Repositories Weaponized to Distribute Windows Malware

A threat actor built a network of 222 GitHub repositories across 190 accounts to distribute Windows malware via malicious Go modules.…

Jul 10, 2026views - 1.8k

malware

GigaWiper: The Post-Compromise Malware Masking Three Destructive Intents

GigaWiper is a modular Go backdoor that unifies wiper, fake ransomware, and spyware capabilities. Linked to BLUERABBIT, the platform c…

Jul 09, 2026views - 1.4k

malware

RedWing: Android Banking Malware Turns into a Telegram Rental Service

Zimperium zLabs uncovered RedWing, a Malware-as-a-Service platform that commercializes Android banking fraud with Telegram bots and su…

Jul 08, 2026views - 1.4k

malware

CAI Worm Kills Rival Cloud Malware, Steals Credentials

The CAI cloud-native worm eliminates TeamPCP and PCPJack processes to monopolize compromised hosts, marking an escalation in criminal…

Jul 07, 2026views - 1.5k

malware

Avalon: The Malware Framework Merging AI and Multi-Evasion to Strike

The Avalon framework combines credential harvesting, multi-EDR evasion, and the CrownX ransomware into a single attack chain. Blackpoi…

Jul 03, 2026views - 1.6k

malware

BusySnake Stealer: The APT That Generates Malware With AI

Armored Likho uses LLMs to write first-stage payloads and PyArmor Pro to obfuscate them. Kaspersky's report reveals an infostealer tar…

Jul 03, 2026views - 1.6k

malware

ToddyCat's Umbrij Malware Steals Gmail OAuth Tokens by Abusing Enterprise Browsers

The Umbrij malware automates OAuth 2.0 token theft via the Chrome DevTools Protocol, bypassing passwords and MFA on corporate Gmail ac…

Jul 02, 2026views - 1.3k

malware

ClickFix Evolves Into a Platform: Analysis of 3,000 Payloads Reveals API-Driven Delivery

A researcher analyzed 3,000 live ClickFix payloads, uncovering an API-driven architecture, rotating cryptographic wrappers, and adopti…

Jul 01, 2026views - 1.2k

malware

ScreenConnect Abused to Deliver AsyncRAT via 90+ Spoofed Freeware Domains

Kaspersky MDR uncovered a large-scale campaign that weaponizes the legitimate remote-access tool ScreenConnect to deploy AsyncRAT thro…

Jul 01, 2026views - 661

malware

RustDuck: The IoT Botnet Rewritten in Rust Challenges Researchers

QiAnXin XLab has tracked RustDuck since February 2026: a two-stage malware rewritten in Rust with enterprise-grade encryption and anti…

Jun 30, 2026views - 1.4k