Malware encompasses trojans, worms, infostealers, and other malicious software used to gain unauthorized access, exfiltrate data, or establish persistent footholds in target environments. defend.network monitors new malware families, variant evolution, and distribution campaigns reported by security researchers and threat intelligence vendors.
WordPress wp2shell RCE under active exploitation with public PoC. NadMesh botnet harvests 3,811 AWS keys from exposed AI services. 7-Zip patches critical archive RCE. Microsoft alerts on ACR Stealer surge.
Two Scattered Spider members sentenced to 5.5 years for 2024 Transport for London attack. Microsoft releases record 570-CVE patch set. ClickLock macOS malware terminates apps until password stolen.
Google and Microsoft remove ModHeader extension (1.6M installs) after discovering hidden tracking. CrashStealer macOS malware evades Gatekeeper using signed code. CISA warns of active Joomla extension exploitation.
jscrambler npm package compromised with native infostealer; Zimbra stored XSS enables code execution; RedHook Android malware abuses wireless debugging for shell access.
jscrambler npm 8.14.0 compromised with Rust infostealer, Zimbra XSS flaw enables code execution
Datadog Security Labs warns of automated campaigns systematically enumerating corporate GitHub organizations via API abuse. Microsoft disassembles destructive GigaWiper backdoor combining disk wipe, ransomware, and spyware. npm 12 disables install scripts by default to reduce supply-chain risk.
North Korean actors publish 108 malicious packages across npm, Packagist, Go, Chrome; Avalon modular framework combines credential theft with CrownX ransomware. U.S. government paid $1M extortion to Kairos group.
North Korean actors published 108 malicious packages across npm and other ecosystems; Linux kernel RCE affects Android; first documented LLM-automated ransomware attack observed.
Google and FBI disrupt 2M-device NetNut proxy network; Anubis ransomware actively exploits Citrix Bleed 2 (CVE-2025-5777); ToddyCat malware abuses Google APIs to hijack Gmail accounts; Microsoft 365 OAuth bypass attacks steal tokens in seconds.
Over 400 Arch Linux AUR packages compromised with credential stealer and eBPF rootkit; China-linked Velvet Ant backdoored Linux authentication for decade; Google sues Chinese phishing-as-a-service using Gemini AI.
Critical threats including TCLBANKER banking trojan, Canvas platform breach disrupting nationwide education, and active Ivanti zero-day exploitation require immediate response across financial, education, and government sectors.
Critical supply chain attacks on developer platforms, Russian state-sponsored token theft via router exploits, and unpatched Windows RPC privilege escalation demand immediate defensive action.
Critical threats include FIRESTARTER backdoor persistence on federal Cisco devices, Russian military token theft via router exploitation, Chinese APT GopherWhisper attacks, and four actively exploited CISA KEV vulnerabilities with May 2026 federal patching deadline.
FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches; Russian state actors harvesting Office tokens via router exploits; four critical CVEs added to CISA KEV with May 2026 deadline; APT campaigns targeting U.S. defense sector; AI-powered phishing escalates to personalized 1-to-1 attacks.
FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches. Russian military intelligence harvesting Office tokens via router exploits. Chinese APT targeting NASA and defense sector with spear-phishing. AI-powered phishing and FakeWallet credential theft escalating.
Critical supply chain attacks via malicious Docker images and npm worms, state-sponsored credential theft campaigns targeting Microsoft Office, and destructive Lotus Wiper malware deployed against Venezuelan energy infrastructure require immediate response across all organizations.
Critical zero-day vulnerabilities in Chrome and TrueConf under active exploitation, combined with widespread malware campaigns targeting mobile and enterprise infrastructure.
Critical supply-chain compromise of Telnyx PyPI package, active iOS exploitation, state-sponsored wiper attacks on medical device firm, and advanced APT malware targeting telecom infrastructure demand immediate response.
Critical supply chain attacks on Trivy scanner and VS Code, destructive Iran-linked wipers targeting Kubernetes, and phishing-as-a-service platforms resurging with 29K IRS victims. Initial access now occurs in 22 seconds.
Subscribe free and never miss a threat briefing.