Research
-
Malwarebytes warns of parcel mule job scams posing as remote work
Malwarebytes says scammers are using fake remote job offers, including “Parcel Expert” roles, to recruit parcel mules who receive and forward stolen goods from home. The company warns of fraud, identity theft and possible law enforcement contact.
-
Mistic backdoor tied to ransomware access broker in attacks on multiple sectors
A new backdoor called Mistic has been used since April in attacks on insurance, education, IT and professional services firms, with researchers linking it to a ransomware access broker that sells network access.
-
Malicious npm packages found posing as PostCSS tools to deliver Windows RAT
Researchers found three malicious npm packages posing as PostCSS tools that delivered a Windows remote access trojan. The campaign used a multi-stage install chain to steal Chrome credentials, run commands and contact an external server.
-
WhatsApp VBScript campaign uses fake documents to spread RMM software
Malicious VBScript files are being spread through WhatsApp messages to install legitimate remote management software, with a Kaspersky technical analysis saying the campaign is active in Malaysia and at least 11 other countries.
-
OpenAI expands Daybreak with GPT-5.5-Cyber update and Patch the Planet initiative
OpenAI said it is expanding its Daybreak effort with an updated GPT-5.5-Cyber model, a new security plugin and a Patch the Planet program aimed at helping defenders find, validate and fix software vulnerabilities faster.
-
FFmpeg fixes PixelSmash flaw that could crash media apps and, in some cases, enable code execution
FFmpeg has fixed CVE-2026-8461, a high-severity MagicYUV decoder flaw that researchers say can crash media apps and, in some cases, enable remote code execution on Jellyfin servers.
-
Researchers detail OXLOADER malware loader used in CastleStealer campaign
Researchers say a new malware loader called OXLOADER is being used to deliver CastleStealer through malicious Google ads, a fake Node.js site, and a Storj-hosted script in a campaign tracked as REF8372.
-
AryStinger malware turns legacy routers into reconnaissance network
AryStinger malware has infected at least 4,300 legacy routers and turned them into a reconnaissance and proxy network, according to a QiAnXin XLab technical analysis. The campaign also has a second strain aimed at QNAP NAS devices.
-
INTERPOL warns of surge in phishing, ransomware and scam centers across Asia and the South Pacific
INTERPOL says cybercrime has surged across Asia and the South Pacific, driven by phishing, ransomware and AI-enabled scams. The report cites more than 135,000 ransomware attacks in 2024 and rising losses from organized fraud networks.
-
Microsoft details AutoJack flaw that could let a web page trigger code on AI agent hosts
Microsoft said a flaw in AutoGen Studio could let a single web page trigger code execution on the host running an AI browsing agent. The issue affects two pre-release PyPI builds, while the stable release is not exposed.







