Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape
Malware Newsletter
UAC-0145 Primary Compromise Vectors as of July 2026
SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor
AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results
UAC-0099: LUNCHPOKE, BURNYBEAR, updated to MATCHBOIL.V2 and using Notepad++ 8.8.3
Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
Symmetric Dual-Domain Prototype Adaptation for Few-Shot Image-Based Malware Classification
Small, Free, and Effective: Orchestrating Open-Weight Small Language Models to Outperform Single LLM for Malware Analysis
(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure
Taming the Security-Energy Paradox: A Green AI Approach to Optimized Android Malware Detection
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, newsletter)

