Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Categorie: malware

Firestarter malware survives Cisco firewall updates, security patches

post, april 24, 2026april 29, 2026

Cybersecurity agencies in the U.S. and U.K. are warning about a custom malware called Firestarter persisting on Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. The backdoor has been attributed to a threat actor that Cisco Talos tracks internally as UAT-4356,…

Continue Reading

Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems

post, april 20, 2026

Cybersecurity researchers have flagged a new malware called ZionSiphon that appears to be specifically designed to target Israeli water treatment and desalination systems. The malware has been codenamed ZionSiphon by Darktrace, highlighting its ability to set up persistence, tamper with local configuration files, and scan for operational technology (OT)-relevant services on the…

Continue Reading

New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection

post, april 7, 2026april 10, 2026

A dangerous Linux backdoor called BPFDoor has returned in a more powerful form, with researchers uncovering new variants built to stay invisible inside critical network infrastructure. Linked to a China-nexus threat actor group known as Red Menshen, these updated versions target Linux servers embedded deep inside global telecom networks. Unlike…

Continue Reading

China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks

post, maart 26, 2026maart 27, 2026

A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to Red Menshen, a threat cluster that’s also tracked as…

Continue Reading

Chinese state hackers target telcos with new malware toolkit

post, maart 5, 2026maart 9, 2026

A China-linked advanced persistent threat actor tracked as UAT-9244 has been targeting telecommunication service providers in South America since 2024, compromising Windows, Linux, and network-edge devices. According to Cisco Talos researchers, the adversary is closely associated with the FamousSparrow and Tropic Trooper hacker groups, but is tracked as a separate activity cluster. This assessment…

Continue Reading

Iran intelligence backdoored US bank, airport, software outfit networks

post, maart 5, 2026maart 9, 2026

An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies’ networks – including a bank, software firm, and airport, among others – since the beginning of February, with more activity in the days following the US…

Continue Reading

CrowdStrike 2026 Global Threat Report

post, februari 24, 2026februari 26, 2026

In the age of AI, even less sophisticated threat actors can execute complex attacks, and advanced adversaries have become dramatically more dangerous. This year’s report exposes the latest tradecraft of the evasive adversary, who is supercharging attacks with AI and posing an unprecedented threat. Attacks by AI-enabled adversaries increased by…

Continue Reading

Predator spyware hooks iOS SpringBoard to hide mic, camera activity

post, februari 21, 2026februari 23, 2026

Intellexa’s Predator spyware can hide iOS recording indicators while secretly streaming camera and microphone feeds to its operators. The malware does not exploit any iOS vulnerability but leverages previously obtained kernel-level access to hijack system indicators that would otherwise expose its surveillance operation. Apple introduced recording indicators on the status bar…

Continue Reading

GitLab Threat Intelligence Team reveals North Korean tradecraft

post, februari 19, 2026februari 23, 2026

Gain threat intelligence about North Korea’s Contagious Interview and fake IT worker campaigns and learn how GitLab disrupted their operations.

Continue Reading

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

post, december 30, 2025januari 5, 2026

The Chinese hacking group known as Mustang Panda (aka HoneyMyte) has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia. The findings come from Kaspersky, which observed the new backdoor variant in…

Continue Reading
  • Previous
  • 1
  • 2
  • 3
  • …
  • 6
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes