Research
-
New Android spyware campaign targets Arabic-speaking users, ESET says
ESET says a new Android spyware campaign called Asin used fake utility, news and war map sites to target Arabic-speaking users. The operation remains unattributed, and its main objective has not been confirmed.
-
Researchers link new OP-512 cluster to IIS server espionage campaign
Researchers found a new China-linked threat cluster, OP-512, targeting Microsoft IIS servers with a custom web shell framework. The activity used timestomping, self-reporting shells and attempted privilege escalation on a legacy Windows Server 2016 host.
-
PCPJack hijacks 230 cloud servers for covert SMTP relay network
PCPJack hijacked 230 cloud servers tied to AWS, Google Cloud and Microsoft Azure to run a covert SMTP relay network, according to Hunt.io. The infrastructure used Sliver and Chisel tools and was still active when found.
-
China-linked TA4922 widens phishing attacks to Europe and South Africa
China-linked TA4922 has expanded phishing campaigns from East Asia to organizations in the U.K., Germany, Italy and South Africa, using malware such as Atlas RAT, RomulusLoader and SilentRunLoader, according to a Proofpoint technical analysis.
-
Researchers say macOS malvertising campaign is spreading FlutterShell backdoor
Researchers say a macOS malvertising campaign has been spreading a new backdoor called FlutterShell through trojanized desktop apps and ads, with activity seen as recently as March 2026.
-
Redis patches two-year-old use-after-free flaw that enabled remote command execution
Redis patched CVE-2026-23479, a use-after-free flaw in blocking-client code that could lead to remote command execution. The bug affected versions 7.2.0 through 8.6.2 and had gone unnoticed for more than two years.
-
Fake open-source tool sites used to push malware through gated redirects
Researchers say fake sites impersonating open-source tools such as Ghidra and dnSpy are using gated redirects to push malware, including Remus Stealer, AnimateClipper and SessionGate, after users click download buttons.
-
Hackers spent months inside stock exchange executive’s Outlook inbox
Unknown attackers spent at least five months inside a senior stock exchange executive’s Outlook mailbox, copying messages in small batches and routing them through Dropbox and OneDrive in what researchers described as espionage.
-
Google patches Gemini flaw that could let poisoned notifications trigger Android actions
Google patched a Gemini on Android flaw that let a poisoned notification influence the assistant, potentially triggering actions from fake messages to smart home controls. SafeBreach said the bug was fixed server-side and no in-the-wild abuse was found.
-
Malspam campaign uses Google DoubleClick redirect chain to deliver DesckVB RAT
A malspam campaign is using Google DoubleClick redirects and personalized phishing pages to deliver DesckVB RAT, a .NET trojan. The attack chain uses HTML attachments, PowerShell, process hollowing, and anti-analysis checks.









