⤷ Title: New Docker Malware Strain Spotted Blocking Rivals on Exposed APIs
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 12:04:37 +0000
════════════════════════
⌗ Tags: #Security #Malware #Akamai #API #Botnet #Cryptomining #Cyber Attack #Cybersecurity #Docker #trend micro
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 12:04:37 +0000
════════════════════════
⌗ Tags: #Security #Malware #Akamai #API #Botnet #Cryptomining #Cyber Attack #Cybersecurity #Docker #trend micro
Hackread
New Docker Malware Strain Spotted Blocking Rivals on Exposed APIs
Akamai finds new Docker malware blocking rivals on exposed APIs, replacing cryptominers with tools that hint at early botnet development.
⤷ Title: Beyond Cryptominers: A New Malware Strain Is Hijacking Exposed Docker APIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:05:45 +0000
════════════════════════
⌗ Tags: #Malware #Akamai #botnet #cryptomining #cybersecurity #Docker malware #exposed APIs #malware evolution #Remote Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:05:45 +0000
════════════════════════
⌗ Tags: #Malware #Akamai #botnet #cryptomining #cybersecurity #Docker malware #exposed APIs #malware evolution #Remote Access
Daily CyberSecurity
Beyond Cryptominers: A New Malware Strain Is Hijacking Exposed Docker APIs
A new malware strain is targeting exposed Docker APIs, evolving from a cryptominer into a stealthy botnet that blocks ports to "own" a victim's system for exclusive use.
⤷ Title: Luno: A “Self-Healing” Linux Botnet That Mines Crypto and Launches DDoS Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Sep 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #botnet #cryptomining #cybersecurity #ddos #Linux #Luno #malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Sep 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #botnet #cryptomining #cybersecurity #ddos #Linux #Luno #malware
Daily CyberSecurity
Luno: A "Self-Healing" Linux Botnet That Mines Crypto and Launches DDoS Attacks
A new Linux botnet, Luno, combines cryptomining and modular DDoS attacks. It's a "self-healing" threat that targets gaming platforms and disguises itself as legitimate processes.
⤷ Title: Morte Botnet Unveiled: A Rapidly Growing Loader-as-a-Service Campaign Exploiting Routers and Enterprise Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 00:05:46 +0000
════════════════════════
⌗ Tags: #Malware #botnet #CloudSEK #Command Injection #cryptomining #Enterprise Security #IOT #Morte Botnet #SOHO Routers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 00:05:46 +0000
════════════════════════
⌗ Tags: #Malware #botnet #CloudSEK #Command Injection #cryptomining #Enterprise Security #IOT #Morte Botnet #SOHO Routers
Daily CyberSecurity
Morte Botnet Unveiled: A Rapidly Growing Loader-as-a-Service Campaign Exploiting Routers and Enterprise Apps
A new Morte botnet campaign is exploiting command injection flaws to hijack SOHO routers and enterprise apps. The Loader-as-a-Service model saw a 230% spike this summer.
⤷ Title: Morte Botnet Unveiled: A Loader-as-a-Service Campaign Hijacking Routers and IoT Devices
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:05:50 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #CloudSEK #Command Injection #cryptomining #DDoS #IoT #Morte Botnet #SOHO Routers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:05:50 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #CloudSEK #Command Injection #cryptomining #DDoS #IoT #Morte Botnet #SOHO Routers
Penetration Testing Tools
Morte Botnet Unveiled: A Loader-as-a-Service Campaign Hijacking Routers and IoT Devices
The Morte botnet campaign is exploiting command injection flaws to hijack SOHO routers and IoT devices for mining and Mirai-style attacks. The operation grew by 230% this summer.
⤷ Title: Hackers Hijack Corporate XWiki Servers for Crypto Mining
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 16:17:42 +0000
════════════════════════
⌗ Tags: #Security #Crypto #Cryptomining #Cybersecurity #Malware #Vulnerability #XWiki
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 16:17:42 +0000
════════════════════════
⌗ Tags: #Security #Crypto #Cryptomining #Cybersecurity #Malware #Vulnerability #XWiki
Hackread
Hackers Hijack Corporate XWiki Servers for Crypto Mining
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
Daily CyberSecurity
Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
Cybereason exposed Tangerine Turkey, a VBScript worm that spreads via USB drives. It uses LOLBins (printui.exe) and Windows Defender exclusions to deploy the XMRig cryptominer for profit.
⤷ Title: AI-Generated Malware Attacks 230,000 Exposed Ray AI Clusters in Massive ShadowRay 2.0 Botnet Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:08:39 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI_generated malware #botnet #cryptomining #CVE_2023_48022 #Oligo Security #Ray AI #ShadowRay 2.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:08:39 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI_generated malware #botnet #cryptomining #CVE_2023_48022 #Oligo Security #Ray AI #ShadowRay 2.0
Daily CyberSecurity
AI-Generated Malware Attacks 230,000 Exposed Ray AI Clusters in Massive ShadowRay 2.0 Botnet Campaign
Oligo exposed ShadowRay 2.0, a massive, evolving campaign using AI-generated malware to turn 230K exposed Ray AI clusters into a self-propagating cryptomining and DDoS botnet.
⤷ Title: Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
Daily CyberSecurity
Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy "Smart Mining" Evasion
ASEC exposed PrintMiner, a Monero cryptominer spreading via USB LNK files. It uses DLL Side-Loading (printui.exe) and "Smart Mining" to suspend activity when games or Task Manager are opened.
⤷ Title: React Under Siege: Two IPs Drive 56% of Critical CVE-2025-55182 Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:12:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptomining #CVE_2025_55182 #DevSecOps #GreyNoise #Patch Alert #React #React Server Components #Remote Code Execution #reverse shell #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:12:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptomining #CVE_2025_55182 #DevSecOps #GreyNoise #Patch Alert #React #React Server Components #Remote Code Execution #reverse shell #Web Security
Daily CyberSecurity
React Under Siege: Two IPs Drive 56% of Critical CVE-2025-55182 Attacks
Critical React flaw CVE-2025-55182 (CVSS 10.0) under mass exploitation. Two IPs drive 56% of attacks deploying miners & shells. Upgrade to v19.0.1+ now.
⤷ Title: Study Finds ROME AI Agent Attempted Cryptomining Without Instructions
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 14:10:08 +0000
════════════════════════
⌗ Tags: #Artificial Intelligence #Machine Learning #Security #Agentic AI #AI #Ai Chatbot #arXiv #Cryptomining #Cybersecurity #Machine Le #ROME AI
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 14:10:08 +0000
════════════════════════
⌗ Tags: #Artificial Intelligence #Machine Learning #Security #Agentic AI #AI #Ai Chatbot #arXiv #Cryptomining #Cybersecurity #Machine Le #ROME AI
Hackread
Study Finds ROME AI Agent Attempted Cryptomining Without Instructions
A study found the ROME AI agent attempted cryptocurrency mining without instructions during training, raising questions about monitoring AI systems.
⤷ Title: The Crypto-Con: Unmasking the Multi-Layered “REF1695” Mining Operation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 03:00:20 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reactor #CNB Bot #Cost Per Action Fraud #CPA Fraud #cryptomining #Elastic Security Labs #infosec #Malware Analysis #Monero #REF1695 #Themida #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 03:00:20 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reactor #CNB Bot #Cost Per Action Fraud #CPA Fraud #cryptomining #Elastic Security Labs #infosec #Malware Analysis #Monero #REF1695 #Themida #XMRig
Daily CyberSecurity
The Crypto-Con: Unmasking the Multi-Layered "REF1695" Mining Operation
Elastic Security Labs unmasks REF1695, a threat actor using the CNB Bot and custom XMRig loaders for Monero mining and CPA fraud. Is your server a silent miner?
⤷ Title: Phorpiex’s New P2P Upgrade Makes This 15-Year-Old Botnet Unstoppable
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 08:16:41 +0000
════════════════════════
⌗ Tags: #Malware #Bitsight #botnet #cryptomining #cybersecurity #Hybrid C2 #infosec #LFI Scanning #P2P Malware #Phorpiex #RSA Encryption #Trik #Twizt
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 08:16:41 +0000
════════════════════════
⌗ Tags: #Malware #Bitsight #botnet #cryptomining #cybersecurity #Hybrid C2 #infosec #LFI Scanning #P2P Malware #Phorpiex #RSA Encryption #Trik #Twizt
Daily CyberSecurity
Phorpiex’s New P2P Upgrade Makes This 15-Year-Old Botnet Unstoppable
Bitsight unmasks the Phorpiex "Twizt" variant: a self-healing P2P botnet with RSA-encrypted payloads and LFI scanners. See how this 2011 threat stays relevant.
⤷ Title: Active Exploitation in the Wild: Critical Qinglong Bypasses Fuel Covert Cryptomining Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 01:01:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #cryptomining #CVE_2026_3965 #CVE_2026_4047 #cybersecurity #Express.js #infosec #Qinglong #rce #Snyk #Task Management
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 01:01:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #cryptomining #CVE_2026_3965 #CVE_2026_4047 #cybersecurity #Express.js #infosec #Qinglong #rce #Snyk #Task Management
Daily CyberSecurity
Active Exploitation in the Wild: Critical Qinglong Bypasses Fuel Covert Cryptomining Campaign
Snyk warns of active in-the-wild exploitation of the Qinglong platform. Two authentication bypass flaws grant attackers RCE to deploy .fullgc cryptominers.
⤷ Title: AI Honeypots Snare Decentralized Cryptominer Dropper
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 06:03:24 +0000
════════════════════════
⌗ Tags: #Malware #Akamai SIRT #cryptomining #Go malware #libp2p #Ollama Security #P2P Malware #threat intelligence #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 06:03:24 +0000
════════════════════════
⌗ Tags: #Malware #Akamai SIRT #cryptomining #Go malware #libp2p #Ollama Security #P2P Malware #threat intelligence #XMRig
Daily CyberSecurity
AI Honeypots Snare Decentralized Cryptominer Dropper
Akamai SIRT uncovers a new P2P cryptominer malware threat. Learn how Ollama endpoint attacks use decentralized libp2p networks to evade detection.
⤷ Title: AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:19:50 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Crypto #Amazon #Amazon Bedrock #Bedrock AI #Cryptomining #Cyber Attack #Cybersecurity #Darktrace #Malware #SSH #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:19:50 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Crypto #Amazon #Amazon Bedrock #Bedrock AI #Cryptomining #Cyber Attack #Cybersecurity #Darktrace #Malware #SSH #Vulnerability
Hackread
AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining
Darktrace says a LiteLLM AI gateway linked to Amazon Bedrock was compromised for cryptomining after signs of exposed SSH activity.
⤷ Title: XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
Daily CyberSecurity
XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
At a glance Field Detail Malware family Modified XMRig 6.25.0 botnet implant (marked “PRIVATE VERSION FOR BOTNET”), cross-compiled with musl libc Threat actor Unidentified; campaign tr…