Malware Security News

Malware families, new samples, and analysis of the techniques malicious software uses to infect and persist on systems.

Malware covers everything from commodity trojans and infostealers to sophisticated custom implants used in targeted intrusions. This feed tracks newly reported samples, family updates and analyst write-ups that break down how a given piece of malware infects, persists and communicates with its operators. It is a useful complement to the ransomware and APT feeds, since most major campaigns rely on custom or repurposed malware.

Recent Malware items

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113 https://ift.tt/RPxuASb
@ctinow · Sep 6, 2026
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores https://ift.tt/hT7Sk8m
@ctinow · Sep 5, 2026
BREAKING - Attackers are exploiting an unpatched Magento and Adobe Commerce ZERO-DAY to backdoor online stores.No login required. No published CVE. No Adobe patch yet.Here's what to do and how the att…
@thehackernews · Sep 5, 2026
Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe https://gbhackers.com/russian-apt28-linked-hackers-deploy-hookedge-backdoor/
@PentestingNews · Sep 5, 2026
European parliament members call for slowdown of Serbia’s EU entry over spyware use https://cyberscoop.com/eu-parliament-serbia-accession-spyware-demands/
@PentestingNews · Sep 5, 2026
lachlanharrisdev/gonetsim: A programmable network simulator for malware analysis; simulate any network protocol with small, sandboxed, shareable Lua handlers. https://github.com/lachlanharrisdev/gonet…
@malwr · Sep 5, 2026
2026-09-01: Essential macOS Stealer infection https://www.malware-traffic-analysis.net/2026/09/01/index.html 🎖
@malwr · Sep 5, 2026
CVE-2026-86144 In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag,…
@cveNotify · Sep 5, 2026
SentinelOne Adds GPT-5.6-Cyber After Malware Analysis Benchmarks https://ift.tt/gUqcwot
@ctinow · Sep 5, 2026
European parliament members call for slowdown of Serbia’s EU entry over spyware use https://ift.tt/ZfvSUMw
@ctinow · Sep 4, 2026
What I Wish I Knew Before Learning Malware Analysis and Reverse Engineering https://kalilinuxtutorials.com/what-i-wish-i-knew-before-learning-malware-analysis-and-reverse-engineering/
@PentestingNews · Sep 4, 2026
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic https://ift.tt/JLXxsfN
@ctinow · Sep 4, 2026
NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft https://gbhackers.com/nodestealer-spyware-malware/
@PentestingNews · Sep 4, 2026
Attackers compiled the newly documented Ted backdoor into HAProxy builds at two South Korean organizations.It keeps C2 out of backend logs and HAProxy statistics while serving altered pages only to se…
@thehackernews · Sep 4, 2026
Sality Malware Disrupted in International Cyber Takedown https://ift.tt/g4HGMOR
@ctinow · Sep 3, 2026
CVE-2026-69414 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". 🎖
@cveNotify · Sep 3, 2026
Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns https://ift.tt/SUNwjen
@ctinow · Sep 3, 2026
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory https://ift.tt/BPztKjR
@ctinow · Sep 3, 2026
StreamRat Android malware spreads through Meta and TikTok ads https://ift.tt/8Vol5Xy
@ctinow · Sep 3, 2026
Criminals can buy access to Windows hosts compromised by BraZetsu.The Python malware uses AI to prioritize high-value systems, collects browser and financial data, and lets buyers deploy their own pay…
@thehackernews · Sep 3, 2026
Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems https://gbhackers.com/rogue-screenconnect-clients/
@PentestingNews · Sep 3, 2026
H1 2026 Malware Vulnerability Trends https://ift.tt/Au3YlJK
@ctinow · Sep 3, 2026
Your Employee’s Password Appeared in an Infostealer Log. Now What? https://ift.tt/xLrZWq5
@ctinow · Sep 3, 2026
Spring Ring’ Vishing Attack Uses Fake IT Calls on Microsoft Teams to Install Malware https://ift.tt/lkXrn0g
@ctinow · Sep 3, 2026
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks https://ift.tt/DtNFU9K
@ctinow · Sep 3, 2026
Attackers are abusing signed Node.js binaries to run malware.Observed activity targeted government departments, tech companies, and hotels. In one intrusion, attackers used ClickFix for initial access…
@thehackernews · Sep 3, 2026
Shai-Hulud now checks 469 locations for credentials.Earlier variants checked 189. The worm now scans developer environments, CI/CD tooling, cloud configs, and AI tool settings. Stolen publishing token…
@thehackernews · Sep 3, 2026
Pegasus infected a Serbian student movement member’s iPhone through a zero-click iMessage exploit.At least 14 people in Serbia have faced advanced spyware targeting in 2026.Read: https://thehackernews…
@thehackernews · Sep 3, 2026
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone https://ift.tt/Y53tMgs
@ctinow · Sep 3, 2026
Earth Berberoka-Linked Hackers Target Brazil With Linux Malware and SEO Poisoning https://gbhackers.com/earth-berberoka-hits-brazil/
@PentestingNews · Sep 3, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.