top of page
download (5).jpg

Malware Tracker

ransomware_tracker.jpg

Ransomware Tracker

C45_Malware_reports.jpg

Malware Reports

Copilot_20260522_174601.png

cyber45 IntelStream

IP-blacklist-300x300_edited_edited_edite

IP Blacklist Check

Latest NEWS

MacSync under the microscope: new delivery methods and a new payload

We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.

24 September 2026

From:

Sergey Puzan [Securelist]

Experts question whether Salesforce demo breaches SAP API policy

For the German vendor, greater challenges may lie ahead, as rivals seek to control the user experience

24 September 2026

From:

[www.theregister.com - Articles]

InfraTrust report warns network management systems under attack

Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]

24 September 2026

From:

Lawrence Abrams [BleepingComputer]

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.

According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below -


@memtensor/memos-cloud-openclaw-plugin versions

24 September 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

The invisible passenger in your car

Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.

24 September 2026

From:

Dmitry Kalinin [Securelist]

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.

The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).

"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file

24 September 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said.

The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal

24 September 2026

From:

info@thehackernews.com (The Hacker News) [The Hacker News]

NightEagle targets Russian companies

Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.

24 September 2026

From:

Stanislav Larinsky, Kaspersky Security Services [Securelist]

Firewall Bug Under Active Attack Triggers CISA Warning

CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.

24 September 2026

From:

Threatpost [Threatpost]

Student Loan Breach Exposes 2.5M Records

2.5 million people were affected, in a breach that could spell more trouble down the line.

24 September 2026

From:

Nate Nelson [Threatpost]

bottom of page