// 2 CRITICAL · 5 ZERO-DAY · 10 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H
malware

Gaslight: macOS Malware Tricks AI Analyzers with Prompt Injection

SentinelOne researchers have documented Gaslight, a previously unknown Rust-based macOS implant that embeds a prompt-injection payload…

Jun 25, 2026views - 750

malware

Edgecution: Malicious Edge Extension Bypasses Sandbox via Native Messaging

Zscaler ThreatLabz documents a campaign where the Edgecution extension abuses Chrome's Native Messaging API to escape the browser sand…

Jun 25, 2026views - 1.2k

linux

Linux Process Masquerading Tricks ps and top

On Linux, malicious processes mask their name and command line by abusing prctl and argv memory overwrites. Standard tools like ps and…

Jun 24, 2026views - 835

malware

Mistic: KongTuke's In-Memory Backdoor Challenges EDR Defenses

Operational since April 2026, the stealthy Mistic backdoor leverages DLL sideloading and in-memory BOF execution for long-term persist…

Jun 24, 2026views - 1.2k

CYBERSECEXPLOIT

StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries

Kaspersky documents the StrikeShark campaign: SharkLoader delivers Cobalt Strike by exploiting known vulnerabilities with public PoCs,…

Jun 24, 2026views - 1.1k

CYBERSEC

The Fake kworker: How APTs Masquerade Linux Processes

Ps and top become unreliable: APTs overwrite argv[0] and use prctl to impersonate kworker. eBPF tools like Kunai detect the real binar…

Jun 24, 2026views - 738

malware

ClickFix macOS: When Users Bypass Gatekeeper Themselves

Microsoft has documented the latest evolution of ClickFix campaigns on macOS: operators have ditched manual DMG installers for Termina…

Jun 23, 2026views - 953

malware

OXLOADER: Malicious Google Ads Deliver Infostealer

Elastic Security Labs uncovers OXLOADER, a previously undocumented Windows loader distributed via malicious Google Ads impersonating N…

Jun 22, 2026views - 755

malware

WhatsApp Weaponized: VBS and RMM Delivered via DMs from Compromised Contacts

An active campaign since June 2026 uses WhatsApp Desktop to distribute malicious VBScript files, install legitimate RMM software, and…

Jun 22, 2026views - 828

CYBERSEC

CSIS Secures First Threat-Reduction Warrant to Disinfect Domestic Botnet

Canada's spy agency obtains the first judicial warrant for active cyber threat-reduction operations on infected routers and IoT device…

Jun 22, 2026views - 1k

malware

Malware on Steam Workshop: Malicious Wallpapers Steal Accounts

Dozens of malicious wallpapers on Steam Workshop have racked up thousands of downloads. Kaspersky analysis reveals DarkKomet backdoor,…

Jun 22, 2026views - 1.6k

CYBERSEC

AryStinger Botnet Compromises Over 4,000 End-of-Life D-Link Routers Worldwide

Qianxin XLab researchers have uncovered AryStinger, a previously undocumented botnet that has hijacked more than 4,000 obsolete D-Link…

Jun 21, 2026views - 830