Microsoft researchers describe ChainDrop, a large-scale npm supply chain attack. The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a large, heavily obfuscated Bun-based JavaScript payload. www.microsoft.com/en-us/securi...
Virus Bulletin
@virusbtn.bsky.social
Security information portal, testing and certification body. Organisers of the annual Virus Bulletin conference.
FortiGuard Labs details a campaign associated with a long-standing supply chain attack on the QuickFox application. QuickFox is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources. www.fortinet.com/blog/threat-...
Netskope Threat Labs exposed a multi-stage SmartLoader chain targeting AI developers via impersonated GitHub repositories hosting popular AI resources, the lures including Claude, ComfyUI, AI coding assistants, Python security guides, and Rust frameworks. www.netskope.com/jp/blog/deve...
Securonix researchers analyse SMOKE#SCREEN, a multi-wave campaign where attackers use rotating social engineering lures - fake Zoom updates, document reviews, and system maintenance tools - to deliver silent ScreenConnect RMM agent installations. www.securonix.com/blog/smoke-s...
Bitdefender researchers look into a malware campaign disguised as an undetected Xeno Roblox script executor variant. Promoted through various gaming forums & Discord communities, the fake cheat launches a multi-stage Java infection chain. www.bitdefender.com/en-us/blog/l...
Zscaler ThreatLabz presents the second part of a technical analysis of new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. This part looks into a new modular stage 3 backdoor: BINDCLOAK, a variant of OctLurk. www.zscaler.com/blogs/securi...
⏰ Only 5 days left to save €200! Secure your place at #VB2026 in Seville before the Early Bird rate ends on 7 August. Join 300+ cybersecurity professionals and 90+ speakers for three days of world-class talks, learning and networking. 🎟️Book now👉https://tinyurl.com/mptv2tx9
Microsoft details CaptiveCrunch, a Storm-2945 (Midnight Blizzard sub-cluster) campaign targeting captive portal traffic at hospitality venues, using doppelganger domains & Entra ID device-code AiTM phishing to deliver malware & steal traveller credentials. www.microsoft.com/en-us/securi...
What was the best piece of technical security research published in the last year? 🔍 Nominations for the 2026 Péter Szőr Award are now open, with the winner to be announced at VB2026 in Seville. 🏆 virusbulletin.com/conference/p... #VB2026 #VirusBulletin #PeterSzorAward
Huntress investigates 6-stage kill chain MacSync: a thin zsh loader, a server-side AppleScript stealer keeping logic behind an API-key gate, a native Mach-O RAT for hands-on access, a signed helper built to steal one TCC permission, & a set of wallet-app trojans. www.huntress.com/blog/macsync...
Bitsight's Pedro Falé uncovers the “Fuyao Enterprise”, a highly modular ad-fraud botnet operating within Android TV boxes. Its operators openly advertise their network of over 120,000 “AI digital humans". www.bitsight.com/blog/fuyao-e...
KnowBe4's Prabhakaran Ravichandhiran & Jeewan Singh Jalal look inside an OS-aware phishing kit that profiles the victim device dynamically and silently routes it into a completely different attack depending on the answer. blog.knowbe4.com/inside-os-aw...
IIJ-SECT's Bynaoki Takayam looks into three of the latest BlueShell variants observed in May 2026, primarily used in attacks by threat actors based in China. sect.iij.ad.jp/blog/2026/07...
Crowdstrike provides a technical deep dive into the Astaroth spambot, examining its overlaps with other recently observed spambots, and exploring what its capability expansion signals about the evolving LATAM e-crime ecosystem. www.crowdstrike.com/en-us/blog/i...
Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 and targeting US & European government entities, as well as the telecommunications, financial, hospitality & aerospace sectors. www.proofpoint.com/us/blog/thre...
Secure your place at #VB2026 in Seville and save €200 on your ticket before the Early Bird rate ends on 7 August. Join 300+ cybersecurity professionals and 90+ speakers for three days of world-class talks, learning and networking. Book your ticket now 👉 tinyurl.com/2t4mt67r
Sophos analysts investigate a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems & facilitate ransomware deployment. www.sophos.com/en-gb/blog/c...
Zscaler ThreatLabz examines four GoGRPC variants from a likely initial access broker for ransomware that leverages vishing techniques through Microsoft Teams. C2 communication protocols & the additional malware tools observed are also analysed. www.zscaler.com/blogs/securi...
Proofpoint reports that Indirect Prompt Injection (IDPI) is increasingly being discussed by malicious actors on closed, underground forums. Tools & services designed to leverage IDPI within attack chains are actively being developed, refined, & advertised for sale. www.proofpoint.com/us/blog/thre...
Ransom-ISAC examines Telegram's role in the malware ecosystem. Its Bot API gives malware authors a free, TLS-protected, globally reachable message bus, with no infrastructure to rent, no domain to burn, and no certificate to manage. ransom-isac.org/blog/the-tel...
JUMPSEC analysed source code from an active BlueNoroff phishing kit used to impersonate Zoom & Microsoft Teams meetings. Operators mistakenly exposed JS source maps on live infrastructure, giving researchers source-level insight into how the operation works. www.jumpsec.com/guides/insid...
Gen has published its H1 2026 Threat Report: Attackers spent the first half of 2026 abusing trust that already exists - hotel workflows, messaging sessions, browser data, developer tools, AI agents, payment habits and identity signals. www.gendigital.com/blog/insight...
Huntress analyst Michael Tigges looks into a malvertising campaign that led to a malicious Claude artifact and to the download of SectopRAT. www.huntress.com/blog/fakeage...
Through ongoing tracking of the TAG-195 MaaS ecosystem, Recorded Future Insikt Group identified four new TAG-195 (Golden Chickens, Venom Spider) malware families: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator. www.recordedfuture.com/research/tag...
Trend Micro researcher Takehiro Iwai uncovered a tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. www.trendmicro.com/en_us/resear...
Microsoft has published its Q2 2026 email threat landscape report - notable campaigns observed demonstrated how threat actors combine automation, trusted services, and multi-stage delivery chains to scale operations. www.microsoft.com/en-us/securi...
Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. www.proofpoint.com/us/blog/thre...
Cisco Talos found a new Rust-based RAT attributed to the Chaos ransomware group. msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution & covert tunnelling for C2 communications. blog.talosintelligence.com/chaos-msarat...
Seqrite's Prashil Moon looks into a multi-stage Phantom stealer malspam campaign disguised as different trusted entities including a global logistics provider and a government tax authority. www.seqrite.com/blog/abusing...
Acronis Threat Research Unit (TRU) has identified an active Lampion malware campaign targeting Portuguese users through phishing emails masquerading as financial and administrative communications. www.acronis.com/en/tru/posts...