top of page
download (5).jpg

Malware Tracker

ransomware_tracker.jpg

Ransomware Tracker

C45_Malware_reports.jpg

Malware Reports

Copilot_20260522_174601.png

cyber45 IntelStream

IP-blacklist-300x300_edited_edited_edite

IP Blacklist Check

Latest NEWS

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.

"Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling

27 July 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.

Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.

"The portal combined build generation, finance,

27 July 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

Watering Hole Attacks Push ScanBox Keylogger

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

27 July 2026

From:

Nate Nelson [Threatpost]

Ransomware Attacks are on the Rise

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

27 July 2026

From:

Nate Nelson [Threatpost]

Flaws in Passkey Implementation Show Old Attacks Still Work

Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.

27 July 2026

From:

Arielle Waldman [darkreading]

When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website

The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.

27 July 2026

From:

Roman Dedenok [Securelist]

A new extortion cocktail: office printers, small ransoms, and BitLocker

We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.

27 July 2026

From:

Eduardo Ovalle [Securelist]

Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects

Kaspersky Compromise Assessment specialists analyze trends from the service's 2025 projects and provide tips on how to enhance your organization's security.

27 July 2026

From:

Victor Sergeev, Amged Wageh [Securelist]

Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms

Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.

27 July 2026

From:

Nate Nelson [Threatpost]

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign

Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.

27 July 2026

From:

Denis Kulik [Securelist]

bottom of page