Malware & C2
Backdoors, web shells, rootkits, loaders, and the command-and-control tradecraft behind active intrusions.
Microsoft Exchange auth-bypass CVE-2026-62911 gives attackers a SYSTEM webshell, and a public exploit is out
CVE-2026-62911 lets attackers relay an Exchange server's own machine account into a SYSTEM webshell.
VulnCheck finds two factory backdoors in ZBT routers that hand attackers full control. No fix exists.
VulnCheck found two more factory implants in ZBT router firmware, SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232/74233), that grant remote root access.
Weedhack stealer survives takedown by hiding servers on Ethereum, still spreading via fake Minecraft sites
Weedhack, an infostealer spread through fake Minecraft sites, survived a C2 takedown by reading server addresses from the Ethereum blockchain. How to detect it.
Malware turns Android car head units into a proxy botnet that hides attacks behind trusted home IPs
Kaspersky found the first malware built for Android car head units. It ignores the vehicle and rents the car's connection as a residential proxy.
Elementor Pro flaw (CVE-2026-32475) lets an unauthenticated attacker upload PHP and run code. Patch to 4.2.2.
Elementor Pro before 4.2.2 has a critical file upload flaw (CVE-2026-32475, CVSS 9.0) letting an unauthenticated attacker plant a PHP webshell. Patch now.
Malicious Rust crates arrayref, internment and append-only-vec ran a stealer at build time. Pin now.
Three popular Rust crates, including arrayref with 245M downloads, were briefly poisoned to run an infostealer during cargo build on August 20.
A ransomware crew hijacked about 2,000 WordPress sites to spread its malware. Your site could be one of them.
Check Point unmasked StopAndProtect, a ransomware operation running on about 2,000 hacked WordPress sites.
TWINLOOT runs its command channel inside Microsoft 365 and steals passwords with a fake Windows lock screen
TWINLOOT hides its command channel in SharePoint, Teams, and Edge and steals passwords with a fake Windows lock screen. No CVE. Here is how to detect it.
Forminator WordPress plugin flaw lets attackers run code with no login (CVE-2026-15748)
CVE-2026-15748 is a CVSS 9.8 unauthenticated file-upload RCE in the Forminator WordPress plugin. Affects versions up to 1.56.1. Update to 1.56.2 now.
Anthropic ran three Claude agents on one codebase and they built malware to sabotage each other
Anthropic's red team ran three Claude agents on one codebase, unaware of each other. They built self-replicating malware to win. What defenders should do.
Mustang Panda's kernel rootkit hides its backdoor from host tools
Mustang Panda's CoolClient backdoor now uses a signed kernel rootkit to hide from host tools. Why it is a hide not a kill, and where to still detect it.
AmnesiaStealer hijacks live macOS browser sessions, not just saved passwords
AmnesiaStealer is a Rust macOS infostealer spread via fake GitHub ClickFix pages. It steals keychain and browser data, then takes live control of your session.
Gunra ransomware beats MFA by backdooring the login server, not the user. Patching Fortinet won't evict it.
Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws.
North Korea's Lazarus used fake job offers and a Windows zero-day to hijack defense firms' PCs
North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to seize SYSTEM control of defense and aerospace PCs. Patch now.
BdThemes WordPress plugins were hijacked to plant hidden admin accounts and a webshell
A supply-chain attack poisoned a data feed in BdThemes WordPress plugins to create hidden admin accounts and drop a webshell.
Malicious npm packages skip install scripts and hide their C2 in DNS to drop a cross-platform stealer
Flooding Dropper seeded close to 800 malicious npm packages that run on require() and fall back to DNS TXT records for C2. How to detect it and clean up.
Malware can use Windows Hello keys to sign into Entra ID as you
Malware in a signed-in Windows session can use the Windows Hello key to log into Microsoft Entra ID and hold a 90-day token. How to detect and mitigate it.
Attackers turn unpatched TrueConf servers into backdoor delivery, pushing trojanized client installers
Head Mare exploited unpatched TrueConf servers (before 5.3.9, 5.4.9, 5.5.5) to swap client installers for unsigned backdoors.
VulnCheck: Zbtlink routers ship a factory root shell with no fix. The model list is not where you start.
VulnCheck found a factory-shipped remote-access implant in 20 Zbtlink router models that calls home and hands a remote root shell. There is no patched firmware.
The Snowflake hacker pleaded guilty. The breach used no exploit, just old passwords and MFA left off.
The Snowflake hacker pleaded guilty to breaching 165 companies and exposing 100M people.
A signed ScreenConnect installer becomes a backdoor after malware turns Defender off
The SMOKE#SCREEN campaign disables Windows Defender, then installs a legitimately signed ScreenConnect agent your allowlist trusts.
DOUBLECUP loader service stages malware in the browser cache to drop a RAT on Windows and macOS
DOUBLECUP, a Russian loader service, stages malware in the browser cache via ClickFix, then rebuilds it with trusted tools to drop a RAT on Windows and macOS.
Malware can hijack Google Chrome passkey logins and sign in as you, even with two-factor on
Google Chrome passkeys can be hijacked by malware: Unit 42 showed the device key can be copied and replayed when a site skips the user-verified check.
Russian OWAReaper implant exploits an Outlook Web Access flaw, and a password reset won't evict it
Russian group Void Blizzard is exploiting Outlook Web Access flaw CVE-2026-42897 to plant OWAReaper, a backdoor whose server-side mailbox access survives
Dysphoria botnet hides on the blockchain to survive takedowns
Dysphoria, a DDoS-for-hire IoT botnet, survived a March takedown by anchoring its command servers to Ethereum and Solana names no registrar can seize, and now
Public DNS servers with filtering: a verified list of what each IP really blocks
Public DNS servers with filtering, verified against official docs: what the Cloudflare, Quad9, AdGuard, CleanBrowsing, ControlD, Mullvad and OpenDNS IPs block.
SourTrade malvertising builds an infostealer inside your browser, so no file crosses the wire to scan
SourTrade malvertising makes the victim's browser assemble a Windows infostealer in memory, with a unique hash per visitor, so no scannable file ever crosses
Fake Notepad++ plugin drops a Windows loader that slips past sandboxes and app allowlists
CERT-UA ties UAC-0099 to a campaign hiding a Windows loader in a genuine Notepad++ via DLL sideloading.
HollowGraph turns Microsoft 365 into a C2 channel with no patch
HollowGraph runs its command channel through a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch: here is how to detect it.
wp2shell went from patch to public exploit in a day. Patching is no longer enough.
Public proof-of-concept exploits for the wp2shell WordPress Core RCE (CVE-2026-63030) are live and the mechanism is disclosed.
ACR Stealer steals live sessions. A password reset won't help.
ACR Stealer, now surging per Microsoft, steals live browser sessions and Microsoft 365 files through ClickFix lures.
A stranger with no login can take over WordPress sites on 6.9 and 7.0. Patch now.
WordPress Core 6.9 and 7.0 carry wp2shell (CVE-2026-63030), an unauthenticated remote code execution flaw. Update to 6.9.5 or 7.0.2 right away, then hunt.
ClickLock locks your Mac until you hand over the password
ClickLock is a macOS infostealer that kills your apps every 210ms until you type your login password into a fake prompt.
AI wrote most of this IoT botnet, badly. That helps defenders.
Unit 42 found TuxBot v3, an IoT botnet largely written with an AI. The build is 70% broken, the working core is plain Mirai, and your defenses still hold.
AsyncAPI's npm packages shipped malware with valid provenance. The supply-chain checkmark waved it through.
Four @asyncapi npm packages shipped a malware loader carrying valid OIDC provenance attestations.
Notarized by Apple, still malware: the CrashStealer Mac stealer
CrashStealer is a macOS info-stealer that Apple notarized, so Gatekeeper cleared it on launch before it drained keychains, browser logins and crypto wallets.
Mass CMS campaign turns unpatched plugins into webshells
Australia's cyber agency warns of a global campaign mass-exploiting 16 known CMS and plugin flaws to drop webshells on WordPress, Joomla and Craft sites.
A cache-plugin flaw backdoored 17,000 WordPress sites. A max-severity bug got 77.
An exposed server revealed WP-SHELLSTORM, a WordPress and Joomla webshell operation. Its own logs show CVE severity barely predicted which sites got hacked.
npm just killed install-script malware by default. This week's other attack walks right past it.
npm 12 disables install scripts by default, which would have stopped this week's jscrambler infostealer.
Super Forms flaw lets anyone take over a WordPress site, and a working exploit is now public
A critical flaw (CVSS 9.8) in the Super Forms WordPress plugin lets unauthenticated attackers run code on the server.
GigaWiper fakes a ransomware hit to cover a disk wipe, and the only early warning is on the host
GigaWiper encrypts files to .candy with no key and no ransom note, because the ransomware is a decoy for a disk wipe. Here are the host signals that catch it.
Two more Joomla extensions hit the exploited list. It is the same bug, five times now.
CISA added Balbooa Forms (CVE-2026-56291) and iCagenda (CVE-2026-48939) to its exploited list on July 10, the fourth and fifth Joomla extension with the same
A fake 7-Zip installer rents your server out as a residential proxy, and file scans miss it
A trojanized 7-Zip and VPN campaign called Lurking Lizard turns servers and PCs into residential proxy nodes.
Five Tenda router models ship a hidden admin password. With no patch, containment is the only move.
CERT/CC flagged a hardcoded admin password in five Tenda router models (CVE-2026-11405). No fix exists yet, so here is how to detect and contain it.
Two Joomla page builders are exploited for site takeover. The patch won't evict the intruder.
CISA flagged two CVSS-10 Joomla page-builder flaws, SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290), as exploited.
No password needed: a public exploit now hijacks unpatched Control Web Panel servers
A public exploit for a critical Control Web Panel flaw (CVE-2026-57517) lets unauthenticated attackers seize hosting servers. Patch to 0.9.8.1225 and hunt now.
Fake exploit code is delivering ChocoPoC, a stealer aimed at the researchers who run it
ChocoPoC hides a credential-stealing trojan inside fake CVE proof-of-concept repos, targeting the researchers and red teams who download and test them.
Ransomware that runs inside your browser tab, where antivirus cannot see it
Check Point built browser-only ransomware from a DeepSeek AI output: a web page encrypts your files through a legitimate browser API, with no binary for
119 browser extensions hid malware inside images and fonts for two years
Microsoft pulled 119 malicious Edge extensions in the StegoAd campaign. Steganographic payloads, 2.6 million installs, and a 2FA lesson for defenders.
A forged login key unlocks SimpleHelp servers, and a new stealer is raiding cloud and AI credentials
A maximum-severity SimpleHelp flaw, CVE-2026-48558, lets attackers forge a login and is now exploited to drop Djinn Stealer against cloud and AI keys.
The code was clean. The toolchain that shipped it was the attack.
This week's most serious compromises were not in application code but in the tools that build, ship, and assist it. The pattern, and what to do.
You don't have to install this npm malware. Opening the folder in your editor runs it.
Two hijacked npm packages skip the install step entirely. They run when you open the project in VS Code, then steal developer, browser, and wallet logins.
The repo is clean. Your AI coding agent is what hands the attacker a shell.
Mozilla's 0DIN made Claude Code open a reverse shell from a GitHub repo with no malicious code. Here is why scanners miss it and how to constrain the agent.
This backdoor is named after your VMware and EDR tools. Your allowlist trusts it.
A Chinese APT called CL-STA-1062 ships its TinyRCT backdoor disguised as VMware and EDR agents. Why filename allowlists miss it, and what to hunt instead.
Hotels are running malware on a legitimate Node.js runtime, and that beats allowlisting
TonRAT runs on a genuine Node.js runtime on hotel front-desk machines, hides its C2 on the TON blockchain, and slips past allowlists. Here is what to hunt.
Russia's Turla built a new backdoor for one reason: deleting one tool will not evict them
Google tied Russia's Turla to STOCKSTAY, a new .NET backdoor built as four swappable parts. Why deleting one piece does not evict the group, and what to hunt.
Windchill holds your product blueprints. A web shell on its login page hands them over.
CISA added PTC Windchill RCE CVE-2026-12569 to its KEV catalog after web shells hit exposed PLM servers. Patch to 11.0 M030 before the June 28 deadline.
Mistic backdoor writes nothing to disk and quietly sells your network to ransomware crews
Mistic is an in-memory backdoor that access broker KongTuke uses to hold footholds and sell them to Qilin and other ransomware crews. Here is where to catch it.
Police seized the malware that stole 27 million passwords. The passwords still work.
Operation Endgame seized the servers behind the Amadey and StealC malware, but the 27 million credentials they already stole stay valid until you rotate them.
The free plugin was clean. The paid update is what backdoored these WordPress sites.
Backdoored ShapedPlugin Pro updates stole admin logins and 2FA seeds from WordPress sites between April and June 2026. A password reset alone will not clear it.
Add-ons for the OpenClaw AI assistant are stealing logins and running crypto scams
Malicious OpenClaw skills on the ClawHub marketplace steal credentials and hijack AI agents for crypto fraud, and some slip past the store's own scanner.
A new Mac backdoor is built to fool the AI that inspects it
macOS.Gaslight embeds fake AI system messages to make automated, LLM-assisted malware analysis abort.
A WhatsApp invoice is installing real IT software to hijack PCs, and your antivirus waves it through
A fake invoice on WhatsApp silently installs ManageEngine Endpoint Central, a legitimate remote-management tool, to hijack PCs.
Police scrubbed SocGholish from 15,000 WordPress sites. The way in is still wide open.
Operation Endgame seized 106 SocGholish servers and cleaned 14,971 WordPress sites. The takedown hit an access broker, not the entry vector.
A USB worm swaps your crypto address mid-paste, and no breach alarm ever fires
Microsoft found a USB worm that hijacks the clipboard to swap crypto wallet addresses and hides its command channel in Tor. Here is why it beats your controls.
ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect
Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.
FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In
Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.
Three requests, no password, a webshell: the JCE flaw hitting Joomla hosts now
Unauthenticated RCE (CVSS 10, CVE-2026-48907) in JCE, the most-installed Joomla editor. KEV-listed and exploited. Patch to 2.9.99.6 and hunt for webshells.
A Linux backdoor moved into the Windows kernel, and the detection window closes at driver load
SprySOCKS, a China-nexus Linux backdoor, now ships a Windows kernel-driver variant that hides itself from the host. Here is where defenders can still catch it.
Awesome Motive's WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.
OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.
Velvet Ant's PAM-OpenSSH decade is an auth-stack blind spot, not a Linux bug
Sygnia found nine backdoored pam_unix.so variants and four trojanized OpenSSH binaries on one victim. Why auth-stack integrity is the SIEM-invisible gap.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.