top of page
download (5).jpg

Malware Tracker

ransomware_tracker.jpg

Ransomware Tracker

C45_Malware_reports.jpg

Malware Reports

Copilot_20260522_174601.png

cyber45 IntelStream

IP-blacklist-300x300_edited_edited_edite

IP Blacklist Check

Latest NEWS

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.

Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider.

"The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment

9 September 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender.

The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month.

"Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

9 September 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.

9 September 2026

From:

Rob Wright, Alexander Culafi [darkreading]

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]

9 September 2026

From:

Lawrence Abrams [BleepingComputer]

Angry Birds: Toy Ghouls’ new toys

Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.

9 September 2026

From:

Kaspersky GERT, Kaspersky Security Services [Securelist]

Microsoft breaks Patch Tuesday record with 974-CVE deluge

Adobe also brought goodies to the patch party and they deserve immediate attention

9 September 2026

From:

[www.theregister.com - Articles]

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.

9 September 2026

From:

Kaspersky [Securelist]

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual.

In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

9 September 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.

"Out-of-bounds write in V8 in Google Chrome prior to

9 September 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.

When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

9 September 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

bottom of page