Android Car Malware Abuses Built-In Updaters to Power Ad Fraud and Proxy Botnets

A new Android malware campaign has been discovered targeting car head units, the systems used for entertainment, navigation, and some vehicle-related functions. Kaspersky researchers identified the threat while monitoring Android attacks in June 2026. The malware is notable because it was delivered through the built-in software updater of affected Android-based automotive head units. Researchers described … Continued

Inside Transparent Tribe’s Upgraded Cyber Toolkit Targeting Afghan Infrastructure

The Pakistan-based cyber espionage group known as Transparent Tribe, or APT 36, has upgraded its digital toolset to launch targeted cyberattacks against major institutions in Afghanistan. Cybersecurity analysts have tracked this active group for years due to its persistent monitoring of neighboring nations. The latest intelligence reports reveal that the hackers are now using updated … Continued

Grandoreiro Malware Returns: New Campaign Targets Mexican Banking Users

Grandoreiro, a banking Trojan that has been active for years, has resurfaced with a new campaign targeting banking users in Mexico. The latest activity shows that the malware is still a serious threat even after law enforcement disrupted parts of its operation. Security researchers found that the campaign is using updated techniques designed to make … Continued

Hackers Can Steal Your Microsoft 365 Session Even After MFA Works

Hackers are using a sophisticated phishing-as-a-service platform called Mirage2FA to target Microsoft 365 users and steal authenticated sessions even after victims successfully complete multi-factor authentication (MFA). Researchers at ANY.RUN found that the Adversary-in-the-Middle (AiTM) framework has generated thousands of potential compromise events from late 2024 through 2026. Instead of directly breaking MFA, the attackers wait … Continued

14,500+ Dahua Devices Compromised in Major Cyberattack Using Multiple Attack Methods 

Cybersecurity researchers at Hunt.io have uncovered a campaign that compromised more than 14,530 Dahua devices between June 17 and July 22, 2026. The campaign, tracked as Operation CameraSwarm, used credential attacks, authentication bypasses, and Dahua’s peer-to-peer (P2P) system. Researchers discovered an exposed 407 MB working directory containing tools, logs, target lists, and other campaign data. … Continued

16 Fake RubyGems Packages Found Stealing Browser Credentials and Crypto Wallets

Cybersecurity researchers have uncovered a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. The activity was discovered by OpenSourceMalware on August 15, 2026, and has been tracked as StubMaker. The campaign involved 16 malicious RubyGems packages designed to look like popular Ruby dependencies. Researchers said the packages were created with small spelling … Continued

TWINLOOT Turns Microsoft 365 Into a Weapon to Steal Credentials and Move Across Networks

Cybersecurity researchers have uncovered a previously undocumented Python-based malware framework called TWINLOOT, which uses trusted Microsoft services to hide its command-and-control activity. Ontinue’s Cyber Defense Center discovered the implant while investigating an active campaign in July 2026. TWINLOOT uses SharePoint Online, Microsoft Teams, and the victim’s own Microsoft Edge browser as part of its communication … Continued

Philips and GE Investigate Clop Claims of Major Data Theft

Philips and General Electric are investigating claims from the Clop ransomware group that the attackers breached their systems and stole company data. Clop has listed both companies on its data leak site as part of a wider campaign targeting dozens of organizations. The group claims that it obtained sensitive information from the affected companies, but … Continued

French Tax Authority Data Breach Exposes Information of 678,000 People and Businesses

France’s tax authority has confirmed a major cyberattack in which attackers accessed government systems and extracted data linked to about 678,000 individuals and professionals. The incident affects the General Directorate of Public Finances, known as DGFiP, which manages taxation and public finance services in France. The breach became public after a threat actor claimed on … Continued

Newsletter line