Malware
15 articles RSS
Malware Attack Forces South Carolina Health System AnMed to Close 79 of 106 Facilities
AnMed shut most of its clinics after a malware disruption hit its network; emergency rooms stayed open and physician offices began reopening Tuesday.
Sysdig Documents JadePuffer, Which It Calls the First Ransomware Attack Run End-to-End by an AI Agent Exploiting a Langflow Flaw
Sysdig says JadePuffer used an LLM agent to exploit Langflow flaw CVE-2025-3248, run 600-plus payloads, and encrypt 1,342 Nacos config items.
Symantec Links a Self-Destructing 'Mistic' Backdoor to the KongTuke Access Broker Feeding Six Ransomware Crews
Symantec ties the in-memory Mistic backdoor to access broker KongTuke, whose footholds have fed Qilin, Akira, Black Basta and other ransomware groups since April 2026.
Operation Endgame Disrupts StealC and Amadey Malware as Microsoft Uses AI and a RICO Suit to Treat Them as One Conspiracy
Law enforcement seized 326 servers and froze 47 million dollars in crypto, while Microsoft filed RICO claims against five defendants after AI tools tied the two malware suites to shared infrastructure.
DAEMON Tools Lite Backdoored for 27 Days: Supply Chain Attack Targeted Government and Scientific Organizations in Russia, Belarus, and Thailand
Kaspersky found official DAEMON Tools Lite installers trojanized from April 8 to May 5, 2026, deploying a multi-stage backdoor to over a dozen targeted machines. CISA added CVE-2026-8398 to its KEV catalog on May 27.
Microsoft Dismantles Fox Tempest, a Malware-Signing Service That Issued Over a Thousand Fraudulent Certificates Through Azure
Microsoft's Digital Crimes Unit seized signspace.cloud and revoked more than 1,000 fraudulent code-signing certificates after Fox Tempest sold access to Azure Artifact Signing for $5,000–$9,000 per transaction to ransomware groups including Rhysida, Akira, and Qilin.
Flashpoint Report Finds Agentic AI Discussions on Criminal Forums Surged 1,500 Percent as Infostealers Fuel 3.3 Billion Stolen Credentials
Flashpoint's 2026 report documents a 1,500 percent spike in AI-related criminal forum activity, 3.3 billion stolen credentials from infostealers, and a 53 percent rise in ransomware incidents.
Qilin Ransomware Group Targets German Political Party Die Linke, Claiming 1.5 Terabytes of Stolen Data
Qilin ransomware group claims attack on German political party Die Linke, threatening to leak 1.5 terabytes of internal data in what the party calls a hybrid warfare operation.
Two Cybersecurity Professionals Face Up to 20 Years in Prison After Pleading Guilty to Running BlackCat Ransomware Attacks
An incident response manager at Sygnia and a ransomware negotiator at DigitalMint admitted to moonlighting as ALPHV/BlackCat affiliates, targeting five US companies and causing over $9.5 million in losses.
Axios npm Package Compromised in Supply Chain Attack Linked to North Korean Threat Actors, Delivering Cross-Platform RAT to Millions of Developers
Attackers hijacked the primary Axios maintainer's npm account and published two malicious versions that installed a cross-platform remote access trojan, exposing one of the JavaScript ecosystem's most downloaded packages.
TeamPCP Supply Chain Attack Reaches LiteLLM as Compromised AI Proxy Package Triggers 500,000 Credential Exfiltrations
Threat actor TeamPCP used credentials stolen in the Trivy compromise to backdoor LiteLLM versions 1.82.7 and 1.82.8 on PyPI, deploying a multi-stage credential stealer across an estimated 500,000 environments.
Europol Coalition Dismantles Tycoon 2FA Phishing Platform That Bypassed MFA at 500,000 Organizations Monthly
A coordinated operation led by Europol, Microsoft, and law enforcement agencies across six countries seized 330 domains powering the Tycoon 2FA phishing-as-a-service platform, which had accounted for 62 percent of all phishing attempts Microsoft blocked by mid-2025.