Securityaffairs

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115


Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

Gray Rabbits and the Tale of a One-Click Backdoor

Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit

Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

The banana stand: brokering and managing infections across Asia using MQTT

Iranian cyber targeting of dissidents, activists and journalists

SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia

Beware the SparroWock: The backdoor that bites, the commands that catch

Brevo supply chain attack hits 100k+ sites with WordPress backdoors and Clickfix malware

Skill Poisioning turning AI agents into malware droppers – warns China’s National CERT

RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts

Brevo supply chain attack hits 100k+ sites with WordPress backdoors and Clickfix malware

The extension you never installed: KREMLIN forges Chrome’s own integrity checks to steal banking sessions

Delphi Scanner: efficient and interpretable static malware detection via API sequence modeling

ALIBI: Adversarial Legitimacy Injection in Binary Input against LLM Malware Analyzers

Metamorphic Malware Detection via Graph-Augmented Neural Semantics and Adversarial Hardening: A Comprehensive Framework

Uncertainty-Aware Zero-Day Botnet Detection for IoT Networks with Real-World Edge Deployment on Resource-Constrained Hardware

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)





Source link