⤷ Title: npm Supply Chain Attack Hijacks Keyv and Spreads Shai-Hulud Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 14:12:20 +0000
════════════════════════
⌗ Tags: #Malware #cacheable #CI/CD security #credential stealer #keyv #npm #Shai_Hulud #Software Supply Chain #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 14:12:20 +0000
════════════════════════
⌗ Tags: #Malware #cacheable #CI/CD security #credential stealer #keyv #npm #Shai_Hulud #Software Supply Chain #supply chain attack
Daily CyberSecurity
npm Supply Chain Attack Hijacks Keyv and Spreads Shai-Hulud Malware
At a glance Malware family Shai-Hulud variant (“Mini Shai-Hulud”) Threat actor Unattributed; linked to the Shai-Hulud lineage and prior TeamPCP and antv campaigns Targets npm and JavaS…
⤷ Title: GenieLocker Ransomware Targets Russian Manufacturers on Windows, Linux, and ESXi
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 02:50:27 +0000
════════════════════════
⌗ Tags: #Malware #Cross_Platform Malware #ESXi Ransomware #GenieLocker #kaspersky #Libsodium #ransomware #Russia Cyberattack #Toy Ghouls
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 02:50:27 +0000
════════════════════════
⌗ Tags: #Malware #Cross_Platform Malware #ESXi Ransomware #GenieLocker #kaspersky #Libsodium #ransomware #Russia Cyberattack #Toy Ghouls
Daily CyberSecurity
GenieLocker Ransomware Targets Russian Manufacturers on Windows, Linux, and ESXi
At a glance Field Detail Malware family GenieLocker (PE builds for Windows; ELF builds for Linux and ESXi) Threat actor Toy Ghouls (also tracked as Bearlyfy, Labubu, Laboo.boo) attribution from OS…
⤷ Title: Critical SonicWall SMA Vulnerabilities Under Attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:43:13 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #ransomware #SonicWall #VPN #vulnerability
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:43:13 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #ransomware #SonicWall #VPN #vulnerability
Information Security News
Critical SonicWall SMA Vulnerabilities Under Attack
The Appeal of VPN Gateways Organizations install VPN gateways at the edge of their corporate networks. They do this specifically so remote employees can securely connect to internal systems. Conse…
⤷ Title: XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
Daily CyberSecurity
XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
At a glance Field Detail Malware family Modified XMRig 6.25.0 botnet implant (marked “PRIVATE VERSION FOR BOTNET”), cross-compiled with musl libc Threat actor Unidentified; campaign tr…
⤷ Title: OctLurk and SilkLurk Backdoors Hit Central Asian Government Networks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 08:11:03 +0000
════════════════════════
⌗ Tags: #Malware #Central Asia Cyberattack #Chinese APT #cyber_espionage #DLL Sideloading #Kaspersky GReAT #OctLurk #PlugX #SilkLurk
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 08:11:03 +0000
════════════════════════
⌗ Tags: #Malware #Central Asia Cyberattack #Chinese APT #cyber_espionage #DLL Sideloading #Kaspersky GReAT #OctLurk #PlugX #SilkLurk
Daily CyberSecurity
OctLurk and SilkLurk Backdoors Hit Central Asian Government Networks
At a glance Field Detail Malware family OctLurk (plugin-based backdoor); SilkLurk (plugin-based backdoor); LurkProxy (network proxy utility) Threat actor Unknown group; assessed with medium confid…
⤷ Title: XCSSET macOS Malware Returns with Stealthy Memory Exploits
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 13:41:38 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #macos #malware #Xcode #XCSSET
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 13:41:38 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #macos #malware #Xcode #XCSSET
Information Security News
XCSSET macOS Malware Returns with Stealthy Memory Exploits
The Resurgence of XCSSET Following several months of quiet activity, a notorious malware family targeting software developers has returned with a stealthy upgrade. This malicious tool leaves almos…
⤷ Title: North Korean Hackers Hide C2 Servers in Ethereum
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 12:41:44 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DPRK #Ethereum #malware #NullReceiver
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 12:41:44 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DPRK #Ethereum #malware #NullReceiver
Information Security News
North Korean Hackers Hide C2 Servers in Ethereum
North Korean cyber syndicates have long sought a method to cloak their command servers. Therefore, they want to render them untraceable and immune to blockades. Now, they utilize a seemingly ordin…
⤷ Title: Shai-Hulud npm Worm Compromises Supply Chain
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 14:20:36 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #JavaScript #malware #npm #Shai_Hulud #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 14:20:36 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #JavaScript #malware #npm #Shai_Hulud #supply chain attack
Information Security News
Shai-Hulud npm Worm Compromises Supply Chain
The Initial JavaScript Breach A single installation of a routine JavaScript library could expose a company’s cloud infrastructure, repositories, and internal services to attackers. The Shai-…
⤷ Title: OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 19:14:21 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Malware #Afghanistan #backdoor #Central Asia #China #Kaspersky #Linux #LurkProxy #MystRodX #OctLurk #PlugX #SilentRaid #SilkLurk #Syria #TrustFall #Windows #WinRAR
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 19:14:21 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Malware #Afghanistan #backdoor #Central Asia #China #Kaspersky #Linux #LurkProxy #MystRodX #OctLurk #PlugX #SilentRaid #SilkLurk #Syria #TrustFall #Windows #WinRAR
Hackread
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
⤷ Title: 45% of Malware C2 Traffic Bypasses DNS by Connecting Directly to IP Addresses
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 13:44:29 +0000
════════════════════════
⌗ Tags: #Malware #C2 Traffic #Direct_to_IP #Malware DNS Bypass #Mozi botnet #Phorpiex #SectopRAT #Unit 42 #ZT_IP Security
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 13:44:29 +0000
════════════════════════
⌗ Tags: #Malware #C2 Traffic #Direct_to_IP #Malware DNS Bypass #Mozi botnet #Phorpiex #SectopRAT #Unit 42 #ZT_IP Security
Information Security News
45% of Malware C2 Traffic Bypasses DNS by Connecting Directly to IP Addresses
Many defensive systems monitor domain name queries as their primary window into outbound malicious activity – but malware families are increasingly circumventing this approach by communicati…