Every story we’ve synthesized.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,611 stories synthesized.
Active Water Saci Campaign Hijacks WhatsApp Web Sessions to Spread Malware via Multi-Vector Persistence
Trend Micro details the Active Water Saci campaign, which uses malicious ZIP files and PowerShell scripts to hijack WhatsApp Web sessions, harvest contacts, and spread malware with sophisticated C&C control.
Lazarus Group Targets European UAV Manufacturers in New Operation DreamJob Wave
ESET researchers have uncovered a new wave of Operation DreamJob attacks by North Korea-linked Lazarus group targeting three European defense companies, including UAV manufacturers, to steal drone technology.
Agenda Ransomware Deploys Linux Variant on Windows Systems via WinSCP and Splashtop
Agenda (Qilin) ransomware has been observed deploying a Linux binary on Windows hosts by abusing WinSCP and Splashtop Remote, evading Windows-centric EDR and targeting backup infrastructure.
SnakeStealer Surges to Become Top Infoste Top Infostealer in H1 2025, Responsible for Nearly One-Fifth of Global Detections
ESET researchers report that SnakeStealer, an infostealer first seen in 2019 in 2019, has become the most detected infostealer in the first half of 2025, accounting for nearly 20% of global infostealer detections.
GitLab Patches Critical Runner Hijack and Multiple DoS Flaws in Emergency Release
GitLab released versions 18.5.1, 18.4.3, and 18.3.5 on October 22, 2025, fixing a critical runner hijack vulnerability and three denial-of-service flaws.
Premier Pass-as-a-Service: How Two China-Aligned APT Groups Are Sharing Access to Stretch Espionage Campaigns
China-linked threat groups Earth Estries and Earth Naga are collaborating through a 'Premier Pass-as-a-Service' model where one group acts as an access broker, handing compromised networks to the other for continued exploitation.
Vidar Stealer 2.0 Rewritten in C with Multithreaded Architecture, Targets Chrome AppBound Encryption
Vidar Stealer 2.0, a complete rewrite in C with multithreaded data theft, bypasses Chrome's AppBound encryption and shows a sharp spike in campaigns since its October 2025 release.
Lumma Stealer Activity Plummets After Doxxing Campaign Targets Core Operators
A targeted doxxing campaign leaked personal details of five alleged Lumma Stealer operators, causing a sharp decline in malware activity and migration of customers to rival infostealers.
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend Micro researchers uncovered Operation Zero Disco, an attack campaign exploiting CVE-2025-20352 to deploy Linux rootkits on Cisco switches.
RondoDox Botnet Expands to Over 50 Exploits, Weaponizing Pwn2Own Flaws in Global Campaign
A large-scale RondoDox botnet campaign is exploiting over 50 vulnerabilities across 30+ vendors, including flaws from Pwn2Own contests, targeting routers, DVRs, and CCTV systems globally.
Cache-Poisoning Attack on TanStack npm Packages Unleashes Credential-Theft Malware with Disk-Wipe Kill Switch
An attacker published 84 malicious versions of TanStack npm packages on May 11, 2026, as part of the ongoing Mini Shai-Hulud campaign, stealing credentials and installing a dead-man's switch that wipes the local disk if a stolen GitHub token is revoked.
China-Aligned APT UTA0388 Uses ChatGPT to Craft Spear-Phishing Emails and Develop Malware
Volexity reveals that China-aligned threat actor UTA0388 has been using OpenAI's ChatGPT to assist in spear-phishing campaigns and malware development, targeting organizations across North America, Asia, and Europe since June 2025.
Axis Plugin Credential Leak Exposes Autodesk Revit Users to Supply Chain Attack
Trend Micro researchers found Azure Storage Account credentials embedded in signed DLLs of an Axis Communications plugin for Autodesk Revit, enabling potential supply-chain attacks.
GitLab Patches Four Vulnerabilities Including High-Severity Authorization and DoS Flaws
GitLab released versions 18.4.2, 18.3.4, and 18.2.8 on October 8, 2025, fixing four vulnerabilities including a high-severity authorization bypass in GraphQL mutations and a denial-of-service flaw.
Trend Micro Details How AI Chatbots Can Be Weaponized as Backdoors in Fictional Attack Chain
Trend Micro Research outlines a step-by-step attack chain showing how AI chatbots can be exploited as backdoors, from initial probing to data exfiltration.
SORVEPOTEL Malware Hijacks WhatsApp Web to Self-Propagate, Targets Brazilian Users
Trend Micro uncovers Water Saci campaign spreading SORVEPOTEL infostealer via WhatsApp, hijacking active sessions to propagate and steal financial credentials.
New Android Spyware Families Target Privacy-Conscious Users in UAE via Fake Signal and ToTok Apps
ESET researchers have uncovered two previously undocumented Android spyware families, ProSpy and ToSpy, that impersonate Signal and ToTok to steal sensitive data from users in the UAE.
Lunar Spider Intrusion Lasted Nearly Two Months After Single Click on Fake Tax Form
The DFIR Report details a May 2024 intrusion by the Lunar Spider initial access group that began with a single click on a malicious JavaScript file masquerading as a tax form and persisted for nearly two months.
DeceptiveDevelopment: North Korea-Aligned Group Targets Developers with AI-Enhanced Fake Job Scams
ESET research reveals DeceptiveDevelopment, a North Korea-aligned threat actor using fake job offers and AI-enhanced fake job offers and synthetic identities to target software developers in the cryptocurrency and Web3 sectors.
New LockBit 5.0 Targets Windows, Linux, ESXi
Trend Micro Research has identified LockBit 5.0 in the wild with Windows, Linux, and ESXi variants, featuring heavy obfuscation, cross-platform targeting, and improved evasion techniques.
GitLab Patches High-Severity XSS and DoS Flaws in Emergency Release 18.4.1
GitLab released versions 18.4.1, 18.3.3, and 18.2.7 on September 25, 2025, fixing multiple security issues including a critical cross-site scripting vulnerability (CVE-2025-9642) and two denial-of-service flaws.
Critical Microsoft Entra ID Vulnerability Allows Global Admin Takeover in Any Tenant
A critical vulnerability in Microsoft Entra ID (formerly Azure AD) allows attackers to obtain Global Admin privileges in any tenant via specially crafted Actor tokens, with no patch yet available.
Salesloft-Drift AI Chatbot Breach Exposes Data of 700+ Companies, Including Cybersecurity Giants
A breach at Salesloft's AI chatbot provider Drift cascaded through the supply chain, exposing data from over 700 organizations including Palo Alto Networks, Cloudflare, and Zscaler.