// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
malware

Lorem Ipsum Pivots to ClickFix After Fox Tempest Takedown

BlueVoyant reports the Lorem Ipsum malware abandoned signed Microsoft Teams installers for ClickFix tactics on compromised WordPress s…

Jun 16, 2026views - 828

malware

DragonForce Weaponizes Microsoft Teams TURN Relays for Stealth C2

The DragonForce ransomware group deployed Backdoor.Turn, the first documented in-the-wild malware to abuse Microsoft Teams' legitimate…

Jun 16, 2026views - 864

malware

SprySOCKS Returns to Windows: Kernel Rootkit and Government Targeting

ESET discovered Windows variants of the SprySOCKS backdoor—previously Linux-only—equipped with a kernel rootkit and used against gover…

Jun 16, 2026views - 978

malware

C0XMO: Gafgyt Variant Targets DD-WRT Routers with Modular Scanner and Competitor-Killing Routine

The C0XMO variant of the Gafgyt botnet exploits CVE-2021-27137 in DD-WRT firmware, utilizing a modular architecture with a standalone…

Jun 07, 2026views - 933

malware

TA4922 Targets Europe with New Atlas RAT and AI-Assisted Malware Development

Proofpoint tracks the European expansion of TA4922, a Chinese-speaking cybercrime group deploying the new Atlas RAT, RomulusLoader, an…

Jun 03, 2026views - 244

malware

JINX-0164: Potential macOS Malware Campaigns Targeting Crypto Developers via LinkedIn

Threat actor JINX-0164 may be targeting cryptocurrency developers through LinkedIn social engineering, potentially utilizing the AUDIO…

May 29, 2026views - 224

malware

BTMOB: The Malware-as-a-Service Erasing Technical Barriers to Android Takeover

ESET researchers have detailed BTMOB, an Android RAT sold as a service featuring a no-code builder. For a $5,000 lifetime fee, even lo…

May 28, 2026views - 218

malware

NGate Malware Trojanizes HandyPay App to Steal Contactless PINs in Brazil

ESET Research has uncovered a new NGate variant that trojanizes the legitimate HandyPay Android app to relay NFC data and intercept PI…

May 24, 2026views - 234

malware

18 Malicious AI Extensions Exposed: Unit 42 Details Email Spying and RAT Risks

Palo Alto Networks Unit 42 has uncovered 18 AI browser extensions that masquerade as productivity tools while deploying RATs and spyin…

May 21, 2026views - 216

malware

BRICKSTORM: CISA and NSA Alert on Evolving Rust Backdoor Targeting vSphere

Cybersecurity agencies have updated their Malware Analysis Report for BRICKSTORM, a sophisticated ELF backdoor targeting VMware vSpher…

May 06, 2026views - 219