Cyber.TechVoid
Read latestCT
HomeLibraryCVEThreatsMalwareResearch

Following

Find topics and threat categories to follow

LatestBreakingVulnerabilitiesThreatsBreachesMalwareCVEResearch
See suggestions
Latest newsCVE trackerRSSllms.txt© 2026

Cyber.TechVoid

Know what happened in cybersecurity today. Source-driven cybersecurity coverage with attribution. Content may be AI-assisted from external feeds and advisories.

Sections

Latest cybersecurity newsData breach newsVulnerability updatesCVE trackerThreat intelligenceMalware watch

Feeds

RSSSitemapNews sitemapllms.txt

© 2026 Cyber.TechVoid. Accuracy over SEO.

TThe Hacker NewsinMalware·Oct 7high

Linux Backdoors Disguised as Email Security Tools Target Telecom Infrastructure in Korea and Taiwan

Researchers have identified Linux-based backdoors targeting telecom and network appliances in South Korea and Taiwan. The malware disguises its network traffic and process names as legitimate email services to blend in with normal administrative traffic and evade endpoint and network security controls. The campaign highlights the ongoing use of defense-evasion techniques that borrow legitimate binary names to avoid detection.

11m
  • Latest
  • Breaking
  • Vulnerabilities
  • Threats
  • Breaches
  • Malware
  • CVE
  • Research
DDark readinginMalware·Oct 7high

ClickFix Attacks Evolve to Better Hide Malicious Payloads

Threat actors have updated their ClickFix social engineering campaign to conceal malicious payloads using DNS TXT records and browser cache pre-fetching techniques. These changes make early detection more difficult, though the core social engineering lure remains unchanged. Security teams are advised to monitor for anomalous DNS activity and browser behavior as part of a layered defense.

11m
TThe Hacker NewsinMalware·Oct 6high

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet with STUN-Based C2

Nozomi Networks researchers report that threat actors have been attempting to exploit a critical vulnerability in the Realtek Jungle SDK. The exploitation delivers Cling botnet malware, which is notable for repurposing ordinary STUN (Session Traversal Utilities for NAT) behavior into a practical command-and-control channel. The vulnerability has since been patched. Users of the Realtek Jungle SDK are advised to update to the latest version to mitigate exploitation risk.

11m
BBleepingComputerinMalware·Oct 6high

Alleged Ploutus Malware Developer Arrested and Appears in US Court

The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, which was used in jackpotting attacks to dispense cash from automated teller machines. The suspect appeared in federal court following the arrest. No further details regarding the defendant's identity or the specific charges were provided in the initial announcement.

11m
DDark readinginMalware·Oct 6high

ClingSTUN Linux Backdoor Exploits 24 IoT Vulnerabilities to Create Proxy Nodes

A newly identified Linux backdoor named ClingSTUN has been observed exploiting 24 known vulnerabilities in IoT devices. Once compromised, the devices are repurposed as proxy nodes that route malicious traffic through legitimate public STUN servers to hide command-and-control communications. The report, initially published by Dark Reading, notes that specific vulnerability details, CVE assignments, and victim counts have not been independently verified.

21m
DDark readinginMalware·Oct 3high

Malicious Linux Implants Mimic Asian Mail Security Products

Security researchers have identified three new Linux backdoors -- KamiKaze, MoRoot, and Watercrack -- that mimic legitimate Asian mail security products. The implants blend into administrative traffic to enable remote code execution and persistence while avoiding detection by traditional security tools.

11m
TThe Hacker NewsinMalware·Oct 2high

WordPress Backdoor SC Self-Heals Using Files, Database, and Shared Memory

Sucuri researchers have detailed a WordPress backdoor codenamed SC that employs multiple persistence mechanisms—including injected files, database entries, and shared memory segments—to ensure the malware self-replicates after apparent remediation. The threat actors embedded "SC_" markers in injected content to facilitate reconstruction of the malicious payload.

12m
TThe Hacker NewsinMalware·Oct 1high

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver Remote Access Trojans (RATs). Huntress observed the activity in late September 2026, marking another instance of abuse in trusted artificial intelligence platforms. The campaign directs victims from AI-generated content to external sites using ClickFix social engineering lures that trick users into executing commands that deliver malware.

11m
BBleepingComputerinMalware·Oct 1high

Russian State Actor Star Blizzard deploys CosmicPulse backdoor via new RedFlick technique

According to BleepingComputer, the Russian state actor Star Blizzard has been observed using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. The report indicates this technique was used in targeted campaigns, though specific exploitation details, target geography, and the scope of affected systems remain unverified. No patch or mitigation guidance specific to RedFlick was provided in the source material.

11m
BBleepingComputerinMalware·Oct 1high

Sponsored ChatGPT Variants Used in ClickFix Attacks to Deploy Remote Access Trojans

Cybersecurity researchers have identified a campaign in which custom variants of OpenAI's ChatGPT are promoted through sponsored Google search results. These malicious links direct users to sites employing ClickFix social engineering tactics, prompting victims to execute commands that result in the deployment of Remote Access Trojan (RAT) malware onto their systems.

11m
DDark readinginMalware·Sep 29high

Chrome Web Store 'Poper Blocker' Extension Exfiltrates User Data

A browser extension named 'Poper Blocker' available on the Google Chrome Web Store has been identified as spyware that exfiltrates sensitive user data. Despite reports from researchers warning of its malicious nature, the extension maintained Google's seal of approval and was downloaded by millions of users before being removed.

11m
TThe Hacker NewsinMalware·Sep 29high

RatHat Android Banking Trojan Console Leverages Gemini AI for Victim Targeting

Cleafy researchers have traced nearly 100 deployments of the RatHat Android banking trojan console since April 2026. The console, operated under a malware-as-a-service model, uses Google's Gemini AI to analyze collected data and identify higher-value victims. Infected devices face financial theft and potential exposure of sensitive data.

11m
TThe Hacker NewsinMalware·Sep 29high

NeedyMantis Malware Used for Long-Term Persistence in Targeted Intrusions

Microsoft has identified a malware family named NeedyMantis being used by threat actors to maintain long-term, unauthorized access to already-breached networks. The malware has been observed in targeted intrusions across a range of sectors, including telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Activity has been tracked since at least 2023 and remains ongoing.

11m
DDark readinginMalware·Sep 29high

Carbonato Botnet Leverages Hermes Agent AI Framework to Compromise Docker Hosts

Security researchers have identified a new botnet campaign, tracked as Carbonato, that repurposes the open-source Hermes Agent AI framework to compromise Docker hosts. The malware leverages exposed container endpoints to execute arbitrary commands through Telegram integration and harvests AI API keys and other sensitive credentials stored on compromised systems.

11m
TThe Hacker NewsinMalware·Sep 29high

CTM360 Report Details ClickFix Evolution From Novelty to Subscription Malware Service

A new global threat report from CTM360 traces the ClickFix malware distribution technique from its emergence in late 2023 to a sophisticated subscription product utilizing on-chain infrastructure and a state-sponsored user base. The report identifies ClickFix as the most common method for attackers to gain initial access to enterprise networks, noting that the technique operates without exploits, attachments, or files on disk, rendering traditional domain blocking ineffective.

11m
TThe Hacker NewsinMalware·Sep 27high

Lunex MaaS Platform Exploits AMD Drivers to Deploy Psychedelic Stealer

Ontinue researchers have identified a new malware-as-a-service operation, Lunex, distributing the Psychedelic Stealer through a four-stage attack chain. The malware abuses AMD graphics drivers to disable security monitoring and exfiltrate browser credentials. Victims are lured through compromised Ukrainian websites hosting fake CAPTCHA pages with ClickFlow-style Cloudflare verification checks. The operation primarily targets Ukrainian-speaking users but has global reach through the MaaS model.

12m
TThe Hacker NewsinMalware·Sep 26high

GitHub Actions Repositories Disabled Again After Mini Shai-Hulud Malware Re-emergence

Two GitHub Actions repositories originally compromised during the May 2026 Mini Shai-Hulud campaign were briefly re-accessible last week before being disabled again. The repositories, actions-cool/issues-helper and actions-cool/maintain-one-comment, are suspected of resuming Mini Shai-Hulud malware execution. GitHub users and organizations relying on these actions face risk to CI/CD pipelines and downstream software supply chains.

11m
TThe Hacker NewsinMalware·Sep 26high

New PamStealer macOS Malware Variant Introduces Server-Side Decryption and Multi-Layer Persistence

Researchers from Jamf Threat Labs have identified a new variant of the PamStealer macOS malware that implements a server-side decryption chain for its main payload. The malware continues to rely on JavaScript for Automation (JXA) droppers but modifies lure and delivery methods. The decrypted payload enables live command-and-control communication and establishes multi-layer persistence on infected systems. No official patch is available; users are advised to avoid executing unknown scripts from untrusted sources.

11m
TThe Hacker NewsinMalware·Sep 25high

Malicious npm Package 'indexed-btree' Disguised as Legitimate Utility

Researchers from Checkmarx have identified a malicious npm package named 'indexed-btree' that impersonated the legitimate 'sorted-btree' package. The threat actor concealed malicious loader code within runtime application logic rather than using traditional npm lifecycle scripts, suggesting a tactical shift to evade security controls. The package has since been removed from the npm registry.

11m
BBleepingComputerinMalware·Sep 25high

New Carbonato Malware Targets Exposed Docker Daemons to Deploy Hermes Agent AI Framework

Security researchers have identified a new botnet malware strain, Carbonato, which targets Docker hosts exposed to the network without authentication. The malware is designed to install the Hermes Agent AI framework on compromised systems, potentially leveraging them for AI workloads or further malicious operations. The report indicates that attackers are scanning the internet for insecure Docker daemon configurations to exploit.

11m
BBleepingComputerinMalware·Sep 25high

MacSync Malware Exploits Public iCloud Calendars to Deliver Native Payloads on macOS

Security researchers have identified a new variant of the MacSync malware targeting macOS systems that uses public iCloud calendar events as a covert mechanism to deliver and execute native malicious payloads. The attack chain leverages calendar events to trigger code execution, though specific technical details of the delivery mechanism remain limited in initial reporting.

11m
DDark readinginMalware·Sep 25high

SectopRAT Returns, Hiding Inside Legitimate Applications

Security researchers have observed a renewed campaign involving SectopRAT, a remote access Trojan that conceals itself within legitimate applications. The tactic is designed to bypass trust-based security controls that rely on software provenance and signing, prompting recommendations for behavior-based monitoring.

11m
TThe Hacker NewsinMalware·Sep 25high

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors compromised legitimate MemTensor packages on the npm and Python Package Index (PyPI) repositories, injecting a platform-specific Go-based implant dubbed 'sckit'. The malware functions as a credential stealer targeting users across Windows, Linux, and macOS operating systems. Security researchers from Aikido, SafeDep, Socket, and StepSecurity identified the compromise, which leverages the trust associated with popular machine learning package names.

11m
TThe Hacker NewsinMalware·Sep 25medium

Cisco Talos Analyzes Novel Windows Malware CLOSEDQUORUM with AI Model Voting Mechanism

Cisco Talos researchers have analyzed a new Windows malware strain designated CLOSEDQUORUM. The malware is designed to route malicious actions through a voting mechanism involving up to four AI models rather than a traditional attacker-controlled command-and-control server. Reported capabilities include the theft of Windows credentials, saved browser passwords, and cryptocurrency wallet data. Talos has not observed the full attack chain functioning end-to-end, and the public version of the malware does not operate as intended.

11m