F5 BIG-IP malware hides web shells in memory to evade detectionSteve ZurierSeptember 9, 2026Memory-resident malware targeting F5 BIG-IP appliances can evade file-based security defenses.
DoppelCart operation uses over 119,000 fake domains to steal payment card detailsSC StaffSeptember 9, 2026
IdentityBigBear 2.0 phishing campaign compromises MFA-protected Microsoft accountsLaura FrenchSeptember 9, 2026Researchers discovered more than 3,300 unique victims across 461 organizations.
PhishingPhishing campaign targets widely used RMM platforms in 46 countriesSteve ZurierSeptember 3, 2026Phishing attacks trick victims into installing legitimate RMM tools for remote access.
MalwareRevStealer malware spread through fake Claude Opus 5 downloadLaura FrenchSeptember 1, 2026The Windows infostealer uses several evasion measures to remain mostly invisible to security systems.
MalwareCodex ClickFix installation lure spreads suspected AMOS infostealerLaura FrenchAugust 25, 2026The attack uses iframes embedded in Google Sites to deliver malicious content from a trusted domain.
Black HatBlack Hat/DEF CON attendees targeted in malware scheme with Google Doc lureLaura FrenchAugust 20, 2026A malicious Google Apps Script sidebar leads to payloads for both macOS and Windows.
RansomwareMedusa ransomware group attacked more than 500 victims since 2021Steve ZurierAugust 19, 2026Medusa ransomware hit 500-plus victims, exploiting critical flaws at increasing speed.
Malware‘TWINLOOT’ Python implant abuses Microsoft services for stealthy C2Laura FrenchAugust 19, 2026The implant ensures defenders only see legit Microsoft services rather than unknown external domains, making it more challenging to block attacks.
RansomwareCISA confirms 2025 Windows Task Host flaw exploited by ransomware groupsSteve ZurierAugust 18, 2026Experts say teams should make this a priority, noting that the patch has been available since last November.
RansomwareMacOS AmnesiaStealer malware spread through ClickFix, grants live browser controlLaura FrenchAugust 14, 2026A fake GitHub download page hosts the malicious ClickFix command.
RansomwareAkira ransomware attacker uses Safe Mode reboot to evade EDRLaura FrenchAugust 12, 2026The ransomware payload ultimately failed to deploy due to insufficient virtual memory.