ZCyberNews — Cybersecurity & Tech Intelligence
HelloNet Campaign Hijacks ViPNet Update System to Deploy Malicious
Kaspersky details HelloNet APT campaign targeting Russian government, energy, and transport sectors via ViPNet update system DLL sideloading since May 2026.
See more updates →4 min read
GoSerpent Backdoor Evolves in Targeted Attacks on Southeast Asian
Kaspersky details the GoSerpent backdoor, active since 2021, targeting government entities in Southeast Asia with a 2026 variant that uses encrypted C2, SOCKS5 proxying, and...
CVE-2023-36036
ModeloRAT Campaign Abuses Microsoft Teams for Enterprise Intrusion
Rapid7 dissects an April 2026 intrusion where a fake IT Support Teams message delivered ModeloRAT via Dropbox, leading to privilege escalation, credential theft, and lateral...
Read →More from today
See all →- 5dMalwareOkoBot: New Sophisticated Malware Framework Targets Cryptocurrency
- 6dAI SecurityAI Crosses From Assistant to Operator in Live Attacks, Check Point
- 1wIndustry NewsCISA Postmortem Reveals GitHub Credential Leak Lasted Six Months
- 1wIndustry NewsEU sues four member states over NIS2 cybersecurity law delays
- 1wIndustry NewsLatvian forestry firm still restoring systems weeks after ransomware
Threat Intel

HelloNet Campaign Hijacks ViPNet Update System to Deploy Malicious
Kaspersky details HelloNet APT campaign targeting Russian government, energy, and transport sectors via ViPNet update system DLL sideloading since May 2026.
Cavern Manticore: Iran-Linked Modular C2 Framework Exposed
Check Point Research tracks Cavern Manticore, an Iran MOIS-linked APT targeting Israeli govt and IT sectors with a modular .NET C2 framework.
ModeloRAT Campaign Abuses Microsoft Teams for Enterprise Intrusion
Rapid7 dissects an April 2026 intrusion where a fake IT Support Teams message delivered ModeloRAT via Dropbox, leading to privilege escalation, credential theft, and lateral...
Vulnerabilities
9.0
critical
CVE-2026-45408: Shell Injection in Dokku PaaS Lets Authenticated
CVE-2026-45408
9.8
critical
CVE-2019-25763: WordPress Beaver Builder Plugin Authentication Bypass
CVE-2019-25763
10.0
critical
CISA Adds Joomla JCE Flaw CVE-2026-48907 to KEV Catalog
CVE-2026-48907
Malware
GoSerpent
RAT
GoSerpent Backdoor Evolves in Targeted Attacks on Southeast Asian
Jul 17 · HIGH
OkoBot
MALWARE
OkoBot: New Sophisticated Malware Framework Targets Cryptocurrency
Jul 15 · HIGH
Browser Ransomware
RANSOMWARE
Browser-Only Ransomware Exploits Chrome File System API via
Jul 1 · HIGH
Industry News
CISA Postmortem Reveals
CISA
CISA Postmortem Reveals GitHub Credential Leak Lasted Six Months
Jul 13 · HIGH
EU
NIS2
EU sues four member states over NIS2 cybersecurity law delays
Jul 10 · INFO
Latvian
RANSOMWARE
Latvian forestry firm still restoring systems weeks after ransomware
Jul 9 · INFO
Tools & Techniques

Metasploit Adds Vim Plugin Persistence, Exploits for Three CVEs
Rapid7's Metasploit Framework adds Vim plugin persistence, exploits for CVE-2025-6793 (Marvell QConvergeConsole), CVE-2024-48760 (GestioIP), and CVE-2023-30253 (Dolibarr).
Signal Adds In-App Warnings to Block Russian-Linked Phishing Attacks
Signal introduced new in-app confirmations and warnings to counter phishing attacks linked to Russian state hackers who abused the Linked Device feature to hijack high-profile...
Anthropic Launches Claude Security for AI-Driven Exploit Defense
Anthropic released Claude Security, a defensive AI suite to counter autonomous exploit tools like Mythos that weaponize zero-days in minutes. Targets enterprise SOCs.
AI Security
AI Security Report 2026
AI SECURITY
AI Crosses From Assistant to Operator in Live Attacks, Check Point
Jul 14 · INFO
Anthropic
PROVIDER
US lifts export controls on Anthropic's frontier cyber AI models
Jul 2 · INFO
Anthropic
AI SECURITY
Mythos AI Excels at Code Audits but Struggles With Exploit Validation
May 14 · INFORMATIONAL
Stay Updated
Get the latest cybersecurity news delivered to your inbox.