Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT.

“The samples employ diverse lure themes, suggesting an effort to appeal to a broad range o… Continue reading Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools→

Posted in Uncategorized

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.

GoCaracal provide… Continue reading GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address→

Posted in Uncategorized

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privil… Continue reading New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access→

Posted in Uncategorized

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, c… Continue reading CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs→

Posted in Uncategorized

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.

The activity … Continue reading FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations→

Posted in Uncategorized

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).

Group-IB, … Continue reading Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler→

Posted in Uncategorized

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process.

In a report … Continue reading NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions→

Posted in Uncategorized

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while re… Continue reading CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing→

Posted in Uncategorized

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it.

The flaws, tracked a… Continue reading Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code→

Posted in Uncategorized