search
malware
Trends
- 1ShinyHunters Claims Breach Exposing FBI Medical Recordsβ(malwarebytes.com) ShinyHunters Exposes Highly Sensitive FBI Medical Records in Extortion-Driven Cyberattack In brief -
The extortion group ShinyHunters claims it breached the FBI and obtained highly sensitive medical records of personnel, reportedly leaked as part of an attempted extortion scheme. Malwarebytes reports on the alleged theft of medical and other private data. The FBI has not been confirmed as commenting, and the scale and authenticity of the claimed leak remain unverified, but the targeting of a US law enforcement agency is drawing close attention in the cybersecurity community.
- 2Gyazo breach exposes data of 23.6 million usersβΌWeek in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Screenshot service Gyazo suffered a data breach affecting 23.6 million users, with personal information exposed. The incident is reported alongside a separate malware operation called TASK#STOMP that steals documents from infected machines. Security observers are treating both as reminders of growing risks around stored user data and targeted document theft, as details of the breach's scope continue to circulate.
- 3New Android malware RatHat records screen touches to steal passwordsβRatHat is a new Android malware that records your screen touches to steal passwords
Security researchers report a new Android malware dubbed RatHat that tracks users' screen touches to capture passwords and other sensitive credentials. By logging tap patterns, the malware can infer what victims type even without a keylogger. Android users are being warned to install apps only from trusted sources and keep devices updated.
- 4
Reports indicate that access to artificial intelligence tools is becoming a commodity traded among cybercriminals, with stolen or resold credentials and subscription accounts allowing low-skill actors to use powerful AI services for fraud, malware and other schemes. The trend lowers the barrier to entry for online crime and raises new questions about how AI providers secure their platforms against misuse.
- 5Group-IB uncovers RemControl, Android banking trojan built with AI helpβGroup-IB uncovers RemControl, the Android banking trojan built with AI help
Cybersecurity firm Group-IB has revealed RemControl, an Android banking trojan that its researchers say was developed with the assistance of artificial intelligence. The discovery highlights how AI tools are lowering the bar for creating malware capable of stealing banking credentials from mobile users. Security teams are expected to examine the trojan's capabilities and update protections against it.
- 6GitHub Actions re-enabled amid Shai-Hulud malware concernsβ# GitHub Actions re-enabled with Mini # ShaiHulud payload still active https://www. bleepingcomputer.com/news/secu rity/
GitHub has re-enabled Actions, but security researchers warn that a smaller variant of the Shai-Hulud payload remains active, keeping supply-chain risk alive for developers who rely on automated workflows. The report, covered by BleepingComputer, suggests teams should stay cautious, audit their pipelines, and treat the malware threat as ongoing rather than resolved.
- 7Group-IB uncovers RemControl Android banking trojanβGroup-IB found the RemControl Android banking trojan, a new malware using AI phishing overlays and fake TVTap apps to st
Cybersecurity firm Group-IB has identified RemControl, a new Android banking trojan distributed through fake TVTap streaming apps. The malware uses AI-generated phishing overlays to trick users into entering banking PINs and credentials, which are then stolen. Security researchers are warning Android users to avoid unofficial app sources as the trojan spreads.
- 8AI malware removes the human from the attack loopβΌhttps://www. csoonline.com/article/4225264/ ai-malware-just-removed-the-human-from-the-attack-loop.html # AImalware # Ma
Cybersecurity commentary is circling a CSO Online piece arguing that AI-powered malware has effectively eliminated the human operator from the attack loop, letting malicious software make its own decisions without direct human control. Security professionals are sharing and debating the claim, with some treating fully autonomous AI malware as a genuine milestone in offensive capability rather than hype.
- 9Lunex Stealer Abuses AMD Driver to Evade Security ToolsβLunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials Source: The Hacker News Rea
Security researchers report that the Lunex Stealer malware abuses a legitimately signed AMD driver to disable security monitoring on infected Windows machines, allowing it to steal saved browser credentials undetected. The technique, known as bring-your-own-vulnerable-driver, exploits a vulnerable driver to gain elevated access and silence endpoint defenses before harvesting sensitive data.
- 10CARBONATO Botnet Uses AI Agent as Its Command-and-Control EngineβΌCARBONATO Is the First Botnet Where the Command-and-Control Engine Is an AI Agent β and It Has Been Running Since October 2024
Researchers describe CARBONATO as the first known botnet whose command-and-control engine is an AI agent, meaning the malware can reportedly make operational decisions itself rather than following fixed instructions from attackers. The botnet is said to have been active since October 2024. Security experts are highlighting the development as a sign that AI is moving into offensive cyber tools, raising concerns about more adaptive and harder-to-take-down botnets.
- 11
Reports from Italian media highlight that malware is growing by 2,065%, with artificial intelligence increasingly being used to power online attacks. The coverage points to a sharp escalation in cyber threats as AI tools make malicious software easier to develop and harder to detect, raising concerns among security experts and prompting debate about how businesses and institutions should respond to this new wave of AI-assisted cybercrime.
- 12Fake TVTap app spreads new Android banking trojan RemControlβPunto Informatico: Falsa app TVTap installa il nuovo malware Android RemControl RemControl Γ¨ un nuovo trojan bancario pe
A fake TVTap app hosted on a site imitating the Google Play Store is distributing RemControl, a new Android banking trojan. Security outlet Punto Informatico reports the malware can target users' banking credentials once installed. The warning is circulating among Italian-speaking tech audiences, who are being urged to avoid third-party app stores and download apps only from official sources.
- 13Wired's NotPetya story resurfaces as a defining cyberattack accountβThe Untold Story of NotPetya, the Most Devastating Cyberattack in History (2018)
Andy Greenberg's 2018 Wired investigation into NotPetya is back in circulation. The piece recounts how the malware, unleashed through Ukrainian tax software in June 2017 and attributed to Russia's military, spread globally and caused roughly $10 billion in damage, crippling Maersk, Merck and pharmaceutical giant Merck's operations. Readers are revisiting the article as one of the definitive accounts of the most costly cyberattack in history.
- 14New PamStealer macOS malware spreads via fake Wavel appsβA new PamStealer macOS infostealer spreads via fake Wavel apps. Learn how the PamStealer macOS infostealer steals system
Security researchers are warning about PamStealer, a new infostealer targeting macOS that is distributed through counterfeit Wavel applications. Once installed, the malware harvests system passwords and browser data from infected machines, putting user credentials at risk. Mac users are being urged to download software only from official sources and to be cautious of fake app installers circulating online.
- 15Hackers exploit Citrix NetScaler zero-day to deploy web shellsβ"Hackers exploit Citrix NetScaler zero-day to deploy web shells" "[...] Cybersecurity firms say attackers exploited the
Cybersecurity firms report attackers are exploiting a previously unknown vulnerability in Citrix NetScaler, tracked as CVE-2026-88772, to deploy custom web shells and tunneling malware. The attackers reportedly gain root access, steal credentials, and move into victims' internal networks. Security teams are urged to check exposed NetScaler appliances for signs of compromise and apply patches as they become available.
- 16SVG phishing attacks surge, Symantec warnsβSVG phishing attacks jumped in August 2026. Symantec explains how SVG smuggling hides fake logins and malware inside ima
Symantec reports a sharp rise in phishing attacks using SVG image files in August 2026. Attackers embed fake login pages and malware inside SVG files smuggled through email attachments, bypassing conventional detection because the files look like harmless images. Symantec has published guidance on how the technique works and what defences organisations should deploy against it.
- 17Bulletproof hosting: the internet's criminal safe havenβΌBulletproof hosting, the Internetβs criminal safe haven # negativepid # digitalInvestigations # OSINT # cybersecurity #
A new explainer examines bulletproof hosting, the practice of internet providers knowingly renting server space to criminals and ignoring abuse complaints or takedown requests. The article outlines how these operators shield malware campaigns, phishing and other cybercrime, and looks at how investigators use open-source techniques to trace and identify the networks behind them.
- 18Attackers use fileless malware delivered via small MSI packageβThe attack isn't rocket science but from an attacker perspective quite neat. The MSI is quite small and contains, appart
Security researchers are discussing a malware attack delivered through a small Windows installer package that contains little obviously suspicious code beyond attacker hostnames. The payload uses a randomly generated readme file to evade signature-based detection, then retrieves its code and executes it directly in memory, leaving minimal traces on disk. Observers describe the technique as technically simple but elegantly effective from an attacker's point of view.
- 19Apple ships new XProtect update for all macOS versionsβApple has released another update to XProtect for all macOS https:// fed.brid.gy/r/https://eclectic light.co/2026/09/30/
Apple has rolled out another update to XProtect, its built-in malware protection system, to Mac users across all supported versions of macOS. The update refreshes Apple's malware signatures and detection rules silently in the background, without requiring a full system update. Mac users and security watchers typically track these releases to gauge emerging threats targeting macOS.
- 20Hackers Hit by New Malware Campaign Targeting CybercriminalsβHakerzy atakujΔ hakerΓ³w z wykorzystaniem zΕoΕliwego oprogramowania. W sieci rozprzestrzenia siΔ nowa kampania zΕoΕliwego
A new malicious software campaign is spreading online, and its main targets are hackers themselves. Reports describe attackers turning their malware against other cybercriminals, a tactic that has drawn attention in cybersecurity circles because it shows criminals exploiting their own tools and channels against rivals.
- 21BinSith open-source Rust binary triage tool releasedβBinSith is now open source! π οΈ A Rust CLI for static binary triage: hashes, strings, indicators, entropy, file compariso
BinSith, a Rust command-line tool for static binary triage, has been released as open source. The tool computes hashes, extracts strings, flags indicators, measures entropy, compares files and scans folders, with JSON and CSV export options. Prebuilt binaries are available for Windows, Linux and macOS, and the code is hosted on GitHub under the vulnex organisation.
- 22Ukrainian researchers warn of mobile malware and iPhone exploit kitβΌMobile malware warning from Ukrainian researchers includes iPhone exploit kit
Security researchers in Ukraine have issued a warning about mobile malware, and their report includes details of an exploit kit targeting iPhones. The disclosure highlights growing concern over smartphone-targeted attacks in Ukraine, a country that has faced sustained cyber operations alongside the ongoing war. The warning serves as an alert to users and defenders to patch devices and watch for signs of compromise.
- 23Fake iPhone Duo preorder scam used to spread DarkSword malwareβΌFake iPhone Duo preorder scam triggers DarkSword attack
Cybersecurity researchers report a scam website posing as a preorder page for an iPhone Duo, which is not a real Apple product. Visitors lured into entering payment or personal details are then targeted with DarkSword, a malicious software attack. The scheme appears designed to exploit hype around new iPhone launches to trick buyers into downloading malware.
- 24Sarcasm greets AI model said to build cyber exploitsβπ€π Bravo, Anthropic! You've managed to cross the fine line between # innovation and # chaos with GLM-5.3, the # AI that
Commenters are mocking the release of GLM-5.3, an AI model they say can generate cyber exploits faster than existing tools. Critics sarcastically congratulate the makers for crossing the line between innovation and chaos, arguing that even 'limited' access to such capabilities amounts to opening a Pandora's box for malware creation and offensive security work.
- 25Critical Citrix NetScaler flaw exploited in the wild since Septemberβπ€ CVE-2026-88772 (CVSS 9.5): DTLS memory overflow in Citrix NetScaler ADC/Gateway lets unauthenticated attackers reach s
A critical vulnerability, CVE-2026-88772 with a CVSS score of 9.5, has been disclosed in Citrix NetScaler ADC and Gateway products. The DTLS memory overflow allows unauthenticated attackers to achieve shellcode execution. According to Mandiant and Google Threat Intelligence, it has been actively exploited since September to gain root access and deploy the WHIPSHOT and SLAPSHOT malware. Administrators are urged to patch immediately.
- 26BSides Luxembourg talk revisits USB malware spreadβ# BSidesLuxembourg2026 recording: "ππ©π«ππππ’π§π πππ₯π°ππ«π ππ’ππ‘ πππ πππ²π¬: ππ¨ππ¬ ππ πππ’π₯π₯ ππ¨π«π€?" by Didier Barzin @ dbarzin & Ma
A recording of a talk titled 'Spreading Malware With USB Keys: Does It Still Work?' by Didier Barzin and Mathieu Vajou has been released from BSides Luxembourg 2026. The security conference talk examines whether USB drives remain a viable vector for distributing malware, with recordings from the track made available via an online archive.
- 27Removable media remains a blindspot in connected retailβΌWhy removable media remains a blindspot in connected retail
Retail is being warned that USB drives and other removable media remain a major blindspot in connected store environments, despite growing cyber security investment across the sector. As retailers connect more tills, kiosks and back-office systems, uncontrolled removable devices can bypass network defences and introduce malware or enable data theft. Security commentators say stricter device control policies are needed.
- 28Malicious ChatGPT Custom GPT Delivers RAT via ClickFix TrickβMalicious ChatGPT Custom GPT pushes RAT via ClickFix https:// fawkes.rocks/2026/09/30/malici ous-chatgpt-custom-gpt-push
Security researchers report a malicious ChatGPT Custom GPT being used to push a remote access trojan through the ClickFix social engineering technique, which tricks users into running commands themselves. The finding highlights how attackers are abusing OpenAI's custom GPT ecosystem as a delivery vector, raising fresh concerns about moderation and vetting of third-party GPTs.
- 29DirtyBlanket Linux Worm Spreads Through Malicious npm Packagesβ(safedep.io) DirtyBlanket: Self-Spreading Linux Worm Distributed via Malicious npm Packages Targeting Developers In brie
Security researchers at SafeDep report a self-spreading Linux worm, dubbed DirtyBlanket, distributed through nine malicious npm packages impersonating popular libraries such as Express and React. Once installed, the malware targets developers' Linux machines and propagates further, making supply-chain attacks on the JavaScript ecosystem a renewed concern for developers reviewing dependencies.
- 30Apple users urged to update devices over code execution flawβπ Security News Digest - 2026-09-29 π 43 updates from 7 sources: π¦ Malwarebytes: Update your iPhone, iPad, or Mac: Flaw
Malwarebytes is warning iPhone, iPad and Mac users to install updates after a flaw was disclosed that could allow attackers to run malicious code on affected devices. The alert is part of a broader security news digest dated 29 September 2026, which rounds up 43 updates from seven cybersecurity sources, including reports from SecurityWeek on other developing incidents.
- 31Microsoft details NeedyMantis malware used in targeted attacksβPosted yesterday, if you missed this. Microsoft: NeedyMantis: Unpacking a post-compromise malware family used in targete
Microsoft has published an analysis of NeedyMantis, a malware family deployed after attackers have already breached a network, with use in targeted operations against specific victims. The report breaks down how the malware behaves once inside a compromised environment. Security researchers and practitioners are sharing the findings, warning organisations to review the indicators of compromise Microsoft disclosed.