Monitor malware campaigns, backdoors, stealers, botnets, trojans, and defender-focused technical reporting. Validate indicators against current primary research before operational use.
Latest intelligence
August 27, 2026
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: Cambodian government and organizational entitiesIncident: Deployment of Spark RAT using a…
August 27, 2026
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: Corporate employees and critical infrastructureIncident: A series of diverse attacks including…
August 27, 2026
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: MediumVictim: Communications organizationsIncident: The deployment of GoCaracal malware within a Venezuelan communications…
August 26, 2026
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: Defense, aerospace, and IT service providersIncident: Discovery of expanded infrastructure and…
August 26, 2026
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: MediumVictim: Organizations utilizing ESET Management AgentIncident: Discovery of the SLEEPWALKER passive backdoor…
August 24, 2026
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
Threat Intelligence Brief Curated summary with source attribution Source: darkreading.com Threat Risk: MediumVictim: Windows usersIncident: The discovery of WordlistLoader, a malware loader used to…
August 24, 2026
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: MediumVictim: Gamers and Minecraft enthusiastsIncident: Distribution of Weedhack malware via spoofed gaming…
August 23, 2026
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111 – Security Affairs
Threat Intelligence Brief Curated summary with source attribution Source: securityaffairs.com Threat Risk: HighVictim: Global enterprises and mobile usersIncident: Multiple concurrent malware campaigns involving ransomware,…
August 23, 2026
Hackers infect Android car head units with proxy botnet malware
Threat Intelligence Brief Curated summary with source attribution Source: bleepingcomputer.com Threat Risk: MediumVictim: Users of DoFun Android car head unitsIncident: A supply-chain attack infected…
August 22, 2026
Malware Hijacks Android Car Head Units
Threat Intelligence Brief Curated summary with source attribution Source: securityaffairs.com Threat Risk: MediumVictim: Users of DoFun Android-based car head unitsIncident: Malware infection of Android…
August 21, 2026
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: MediumVictim: Android-based vehicle head unit usersIncident: Malware distribution via compromised automotive firmware…
August 21, 2026
Medical records, SSNs, and bank details exposed in CareCloud data breach | Malwarebytes
Threat Intelligence Brief Curated summary with source attribution Source: malwarebytes.com Threat Risk: HighVictim: CareCloudIncident: Unauthorized access to an AWS environment resulting in a large-scale…
August 20, 2026
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: Rust developers and CI/CD pipelinesIncident: A supply chain attack involving the…
August 20, 2026
‘Grandoreiro’ Malware Resurfaces With Mexico Campaign
Threat Intelligence Brief Curated summary with source attribution Source: darkreading.com Threat Risk: MediumVictim: Banking customers in Mexico and Latin AmericaIncident: Resurgence of the Grandoreiro…
August 20, 2026
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: Financial institutions and government agencies in Europe and UkraineIncident: Discovery of…
August 19, 2026
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: Organizations and individuals visiting compromised WordPress sitesIncident: A global campaign utilizing…
August 19, 2026
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: macOS users and organizationsIncident: Deployment of MacSync Stealer via social engineering…
August 18, 2026
Heights Finance data breach: What customers need to know | Malwarebytes
Threat Intelligence Brief Curated summary with source attribution Source: malwarebytes.com Threat Risk: HighVictim: Heights Finance Holdings customersIncident: Unauthorized access to a third-party cloud platform…
August 17, 2026
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: Internet-facing Linux-based edge devicesIncident: Deployment of the Evooo1Bot botnet via exploitation…
August 17, 2026
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: MediumVictim: General internet users and enterprisesIncident: Widespread acquisition of expired domains to…
August 16, 2026
Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl & Others) | InfoStealers
Threat Intelligence Brief Curated summary with source attribution Source: infostealers.com Threat Risk: HighVictim: Fortune 500 EnterprisesIncident: Mass exfiltration of employee directory data from Azure…
August 11, 2026
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: Android TV and Linux IoT device usersIncident: The emergence of Kimwolf…
August 11, 2026
Striking gold: Inside the GoldDigger Android malware | IBM
Threat Intelligence Brief Curated summary with source attribution Source: ibm.com Threat Risk: HighVictim: Android mobile banking usersIncident: Deployment of the GoldDigger banking Trojan to…
August 10, 2026
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Threat Intelligence Brief Curated summary with source attribution Source: thehackernews.com Threat Risk: HighVictim: Organizations using Metabase and open-source project maintainersIncident: Exploitation of a CVSS…