Skip to content

Latest alerts

RSS feed

SilverFox uses BYOVD and DLL sideloading

A cybercriminal group, Silver Fox, targeted a Japanese organization in the industrial manufacturing sector. With BYOVD and DLL sideloading, ValleyRAT is delivered for long-term remote access.

Google Password Manager: malware bypasses passkeys

Unit 42 investigated how malware on a Windows PC can abuse passkey-protected accounts via Google Password Manager in Chrome. The attack is post-compromise: it only starts once the device has already been taken over.

INC ransomware: SonicWall SMA 1000 vulnerabilities

Resecurity reports that INC ransomware has been claiming victims faster since the beginning of August 2026 via SonicWall SMA 1000. The chain appears to be driven by zero-days that, among other things, abuse MFA seeds and credentials.

Cyberattack on Economic Beneficiaries Register

Liechtenstein reports that a cyberattack accessed the economic beneficiaries register, impacting around 31,000 people. Authorities say they took immediate steps and saw no signs of data tampering.

BTMOB RAT: how a MaaS ecosystem grows underground

BTMOB RAT began as malware-as-a-service for Android, but evolved into a fragmented ecosystem with resellers, source code buyers, and alleged imitators. Flare followed the evolution of 2025 to 2026 in underground forums and chat channels.