← All Intelligence

Malware Threat Intelligence

10 briefings0 vulnerability reports

Malware encompasses trojans, worms, infostealers, and other malicious software used to gain unauthorized access, exfiltrate data, or establish persistent footholds in target environments. defend.network monitors new malware families, variant evolution, and distribution campaigns reported by security researchers and threat intelligence vendors.

10
briefings
0
critical
2
high
11%
of all briefings

Threat Briefings

2026-06-13

Arch Linux supply-chain worm, Velvet Ant backdoor, Gemini phishing-as-a-service

Over 400 Arch Linux AUR packages compromised with credential stealer and eBPF rootkit; China-linked Velvet Ant backdoored Linux authentication for decade; Google sues Chinese phishing-as-a-service using Gemini AI.

2026-05-09

TCLBANKER trojan; Canvas breach hits education; Ivanti zero-day

Critical threats including TCLBANKER banking trojan, Canvas platform breach disrupting nationwide education, and active Ivanti zero-day exploitation require immediate response across financial, education, and government sectors.

2026-04-28

Developer platform supply-chain attacks; Windows RPC zero-day

Critical supply chain attacks on developer platforms, Russian state-sponsored token theft via router exploits, and unpatched Windows RPC privilege escalation demand immediate defensive action.

2026-04-27

FIRESTARTER federal Cisco persistence; Chinese APT GopherWhisper

Critical threats include FIRESTARTER backdoor persistence on federal Cisco devices, Russian military token theft via router exploitation, Chinese APT GopherWhisper attacks, and four actively exploited CISA KEV vulnerabilities with May 2026 federal patching deadline.

2026-04-26

FIRESTARTER on federal Cisco gear; 4 critical CVEs added to CISA KEV

FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches; Russian state actors harvesting Office tokens via router exploits; four critical CVEs added to CISA KEV with May 2026 deadline; APT campaigns targeting U.S. defense sector; AI-powered phishing escalates to personalized 1-to-1 attacks.

2026-04-25

FIRESTARTER persists on federal Cisco; APT spear-phishes NASA

FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches. Russian military intelligence harvesting Office tokens via router exploits. Chinese APT targeting NASA and defense sector with spear-phishing. AI-powered phishing and FakeWallet credential theft escalating.

2026-04-23

Docker & npm supply-chain hits; Lotus Wiper on Venezuelan energy

Critical supply chain attacks via malicious Docker images and npm worms, state-sponsored credential theft campaigns targeting Microsoft Office, and destructive Lotus Wiper malware deployed against Venezuelan energy infrastructure require immediate response across all organizations.

2026-04-02

Chrome & TrueConf zero-days exploited; widespread malware campaigns

Critical zero-day vulnerabilities in Chrome and TrueConf under active exploitation, combined with widespread malware campaigns targeting mobile and enterprise infrastructure.

2026-03-28

Telnyx PyPI compromise; iOS exploit active; APT hits telecom

Critical supply-chain compromise of Telnyx PyPI package, active iOS exploitation, state-sponsored wiper attacks on medical device firm, and advanced APT malware targeting telecom infrastructure demand immediate response.

2026-03-24

Trivy & VS Code supply-chain breach; Iran wipers hit Kubernetes

Critical supply chain attacks on Trivy scanner and VS Code, destructive Iran-linked wipers targeting Kubernetes, and phishing-as-a-service platforms resurging with 29K IRS victims. Initial access now occurs in 22 seconds.

Get the Daily Briefing in Your Inbox

Subscribe free and never miss a threat briefing.