Firestarter malware survives Cisco firewall updates, security patches post, april 24, 2026april 29, 2026 Cybersecurity agencies in the U.S. and U.K. are warning about a custom malware called Firestarter persisting on Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. The backdoor has been attributed to a threat actor that Cisco Talos tracks internally as UAT-4356,… Continue Reading
Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems post, april 20, 2026 Cybersecurity researchers have flagged a new malware called ZionSiphon that appears to be specifically designed to target Israeli water treatment and desalination systems. The malware has been codenamed ZionSiphon by Darktrace, highlighting its ability to set up persistence, tamper with local configuration files, and scan for operational technology (OT)-relevant services on the… Continue Reading
New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection post, april 7, 2026april 10, 2026 A dangerous Linux backdoor called BPFDoor has returned in a more powerful form, with researchers uncovering new variants built to stay invisible inside critical network infrastructure. Linked to a China-nexus threat actor group known as Red Menshen, these updated versions target Linux servers embedded deep inside global telecom networks. Unlike… Continue Reading
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks post, maart 26, 2026maart 27, 2026 A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to Red Menshen, a threat cluster that’s also tracked as… Continue Reading
Chinese state hackers target telcos with new malware toolkit post, maart 5, 2026maart 9, 2026 A China-linked advanced persistent threat actor tracked as UAT-9244 has been targeting telecommunication service providers in South America since 2024, compromising Windows, Linux, and network-edge devices. According to Cisco Talos researchers, the adversary is closely associated with the FamousSparrow and Tropic Trooper hacker groups, but is tracked as a separate activity cluster. This assessment… Continue Reading
Iran intelligence backdoored US bank, airport, software outfit networks post, maart 5, 2026maart 9, 2026 An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies’ networks – including a bank, software firm, and airport, among others – since the beginning of February, with more activity in the days following the US… Continue Reading
CrowdStrike 2026 Global Threat Report post, februari 24, 2026februari 26, 2026 In the age of AI, even less sophisticated threat actors can execute complex attacks, and advanced adversaries have become dramatically more dangerous. This year’s report exposes the latest tradecraft of the evasive adversary, who is supercharging attacks with AI and posing an unprecedented threat. Attacks by AI-enabled adversaries increased by… Continue Reading
Predator spyware hooks iOS SpringBoard to hide mic, camera activity post, februari 21, 2026februari 23, 2026 Intellexa’s Predator spyware can hide iOS recording indicators while secretly streaming camera and microphone feeds to its operators. The malware does not exploit any iOS vulnerability but leverages previously obtained kernel-level access to hijack system indicators that would otherwise expose its surveillance operation. Apple introduced recording indicators on the status bar… Continue Reading
GitLab Threat Intelligence Team reveals North Korean tradecraft post, februari 19, 2026februari 23, 2026 Gain threat intelligence about North Korea’s Contagious Interview and fake IT worker campaigns and learn how GitLab disrupted their operations. Continue Reading
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor post, december 30, 2025januari 5, 2026 The Chinese hacking group known as Mustang Panda (aka HoneyMyte) has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia. The findings come from Kaspersky, which observed the new backdoor variant in… Continue Reading