Malware Security News

Malware families, new samples, and analysis of the techniques malicious software uses to infect and persist on systems.

Malware covers everything from commodity trojans and infostealers to sophisticated custom implants used in targeted intrusions. This feed tracks newly reported samples, family updates and analyst write-ups that break down how a given piece of malware infects, persists and communicates with its operators. It is a useful complement to the ransomware and APT feeds, since most major campaigns rely on custom or repurposed malware.

Recent Malware items

Apple warned hundreds of users of mercenary spyware attackshttps://ift.tt/oMJKPWY
@ctinow · Aug 14, 2026
Agentic AI Models Rebuild Malware and Sustain Real-World Cyber Intrusions, SentinelOne Warnshttps://gbhackers.com/agentic-ai-models-rebuild-malware/
@PentestingNews · Aug 14, 2026
Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malwarehttps://ift.tt/7Cym5V3
@ctinow · Aug 14, 2026
Apple now uses iPhone alerts for targets of mercenary spywarehttps://ift.tt/JjV2Yo4
@ctinow · Aug 14, 2026
CoolClient now uses a signed rootkit to hide at the Windows kernel level.The Mustang Panda-linked backdoor can hide its process, files, registry entries, and some C2 activity.Kaspersky found victims i…
@thehackernews · Aug 14, 2026
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkithttps://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
@PentestingNews · Aug 14, 2026
Agentic AI Models Rebuild Malware and Sustain Real-World Cyber Intrusions, SentinelOne Warnshttps://ift.tt/IFulg9i
@ctinow · Aug 14, 2026
Dysphoria Hijacks Routers, Gateways and IP Cameras to Build Massive IoT Botnethttps://gbhackers.com/dysphoria-hijacks-routers/
@PentestingNews · Aug 14, 2026
Expired domains are a goldmine for hackers – and some cyber crime groups are investing millions in 'dropcatch' scams to deliver malwarehttps://ift.tt/fIFbWpS
@ctinow · Aug 14, 2026
Mercenary spyware may have targeted users in 110 countries.Apple has sent a fresh round of high-confidence alerts to people it says were individually singled out. Journalists, activists, politicians,…
@thehackernews · Aug 14, 2026
AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsershttps://securityaffairs.com/197190/malware/amnesiastealer-gives-attackers-live-control-of-victims-macos-browsers.html
@PentestingNews · Aug 14, 2026
Apple Warns iPhone Users in 110 Countries of Mercenary Spyware Attackshttps://gbhackers.com/apple-warns-iphone-users-in-110-countries/
@PentestingNews · Aug 14, 2026
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkithttps://ift.tt/IoMRJ3Y
@ctinow · Aug 14, 2026
New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPLhttps://ift.tt/utxqSEP
@ctinow · Aug 14, 2026
Aeternum Hides Malware Commands on Polygon Blockchain Where Server Takedowns Can’t Erase Themhttps://gbhackers.com/aeternum-hides-malware-commands/
@PentestingNews · Aug 14, 2026
New AmnesiaStealer Malware Targets macOS Users via ClickFix Attackshttps://gbhackers.com/new-amnesiastealer-malware-targets-macos-users/
@PentestingNews · Aug 14, 2026
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessionshttps://ift.tt/ZycenoI
@ctinow · Aug 14, 2026
When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg - Malware Analysis BlogTaking apart a freshly compiled Interlock ESXi decryptor, and what it reveals about how the encryptor…
@malwr · Aug 14, 2026
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attackshttps://ift.tt/5une3dL
@ctinow · Aug 14, 2026
This week’s threats came from everywhere.AI agents tricked through poisoned data. Cloud services exposed through guest access. Fake software dropping spyware. DDoS attacks getting bigger. New scams, m…
@thehackernews · Aug 13, 2026
Jewelbug Uses Public Google Docs as Malware Command-and-Control Delivery Channelhttps://gbhackers.com/jewelbug-uses-public-google-docs/
@PentestingNews · Aug 13, 2026
CVE-2026-73533Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introdu…
@cveNotify · Aug 13, 2026
CVE-2026-73532Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduc…
@cveNotify · Aug 13, 2026
Malware Crypting Services and the Threat Actors Who Sell ThemInsikt Group analyzes 24 threat actors selling malware crypting services. Learn about their evasion techniques, market dynamics, and how de…
@malwr · Aug 13, 2026
The Model Is the Malware | What Four Agentic Intrusions Tell Defendershttps://www.sentinelone.com/labs/the-model-is-the-malware-what-four-agentic-intrusions-tell-defenders/
@PentestingNews · Aug 13, 2026
Malware Crypting Services and the Threat Actors Who Sell Themhttps://ift.tt/kbM89Tx
@ctinow · Aug 13, 2026
Malware attack forces California city to declare emergency, disrupts 911https://ift.tt/IehsyRU
@ctinow · Aug 13, 2026
New Android malware lets criminals use your bank card in real timehttps://ift.tt/Zxv8ebS
@ctinow · Aug 13, 2026
WindRelay turns Android phones into live contactless payment proxies.Attackers use SpyNote access to silently install the NFC relay malware. When victims tap a physical card on the infected phone, Win…
@thehackernews · Aug 13, 2026
Storm-1175 Replaces Medusa With New StormEncryptor Ransomwarehttps://securityaffairs.com/197119/malware/storm-1175-replaces-medusa-with-new-stormencryptor-ransomware.html
@PentestingNews · Aug 13, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.