Threat Research

    Researchers details active exploitation of CVE-2026-73570, an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path, allowing attackers to execute commands on internet-facing servers without authentication....
    Threat actors are actively exploiting two critical NetScaler ADC and Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated CVSS 4.0: 9.5. CVE-2026-88771 enables unauthenticated remote code execution through improper input validation, while CVE-2026-88772 can cause RCE or DoS through a DTLS memory overflow....
    Identified UAT-11587 targeting government and policy organizations across Asia, including Taiwan, India, the Philippines, and Cambodia. First observed in September 2025, the activity had affected or targeted at least 16 institutional environments across eight Asian countries by July 2026....
    Researchers report that Russian Star Blizzard (SEABORGIUM) has expanded its phishing operations in 2026, using large-scale phishing campaigns, compromised websites, and social engineering to target organizations, particularly those connected to Ukraine....
    Detects potential arbitrary file downloads initiated through Microsoft Office applications....
    The AgtaBackup RAT campaign uses fake Microsoft Store/video-conferencing pages to deliver legitimate RMM tools such as LogMeIn Resolve and ConnectWise ScreenConnect, giving attackers remote access to victim systems. Attackers then use PowerShell to download and silently install the .NET-based AgtaBackup RAT as a hidden SYSTEM service....
    Researchers identified a coordinated Malicious Browser Extension campaign in which Chrome extensions disguised as browser games impersonate legitimate Crypto Wallets such as TronLink, Trust Wallet, and Ledger Wallet Extension....
    NeedyMantis is a modular post-compromise malware family used in targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, it is typically deployed after initial access to maintain long-term persistence and support follow-on operations....
    Attackers are abusing ChatGPT Custom GPTs to impersonate legitimate products and redirect victims to malicious backup sites. The team identified two Custom GPTs linked to the same campaign and used to facilitate the attacks. A ClickFix lure tricks victims into executing PowerShell, which downloads a malicious MSI and launches a multi-stage infection chain....
    Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), with expanded targeting across multiple sectors. In June 2026, the threat actor primarily exploited the vulnerability as a zero-day against academic institutions....
    Threat actors used fraudulent Google Ads to target Ledger hardware wallet users with a phishing campaign. The ads redirected victims through Google Cloud Storage and frequently changing Vercel domains to a fake Ledger page hosted through Google Sites....
    Researchers highlight a Social Engineering campaign using attractive shipping-rebate offers to lure users into deceptive subscription programs with recurring monthly charges. The Phishing-style offers can obscure billing terms and lead victims to unknowingly enroll in paid memberships, making this an Online Fraud and Financial Scam....
    Vidar is an information-stealing malware first observed in 2018 that has continued to evolve its string obfuscation techniques. Its developers have modified deobfuscation algorithms, constants, and primitives to make detection and analysis more difficult. From May to early September 2026, ThreatLabz tracked Vidar’s progression from basic XOR-based obfuscation to ChaCha20....
    Researchers uncovered a SectopRAT (ArechClient2) variant hidden inside a legitimate Italian audio workstation application. Attackers tampered with FrameworkBase.dll to sideload sdkcra.dll, while the encrypted SectopRAT payload was embedded in legitimate-looking database files and launched through a scheduled task....
    The new MacSync macOS infostealer uses revamped binary-based delivery, with Objective-C/Swift payloads and DMG-based infection chains, including abuse of iCloud Calendar for payload delivery. The malware employs AES encryption, ECDH Curve25519, anti-debugging, and in-memory execution while establishing persistence through LaunchAgents, ZSHRC, and Git hooks....
    Looking for Something?
    Threat Research Categories:
    Tags