ZCyberNews
中文

Articles

497 articles

Abstract digital representation of a ransomware attack targeting corporate networksHIGH
Malware

Pro-Ukraine VantaCore Ransomware Hits Russian Firms

Pro-Ukraine group VantaCore, a rebrand of Thor, has hit at least 7 Russian firms with custom ransomware and RATs, demanding millions in ransom, per F6.

4 min readVantaCore
ATM machine with a warning sign, illustrating the jackpotting attack vector discussed in the article.
Malware

Five Plead Guilty in Federal ATM Jackpotting Case

Five Venezuelan nationals pleaded guilty to bank larceny for ATM jackpotting in Kansas. FBI reports over $58M in losses since 2021 and 1,900 incidents since 2020.

3 min readTren de Aragua
Illustration of a laptop with a fake coding job offer and malware symbolsHIGH
Malware

Iranian cyber spies target aviation, fintech developers with new

Iran's Mirage Kitten lures aviation, fintech developers with fake coding tests, deploying new NodeRabbit and PollCat malware across Windows, Linux, and macOS.

4 min readMirage Kitten
Diagram showing the JSCeal infection flow from malvertising to Node.js executionHIGH
Malware

Breaking the Seal: Static Deobfuscation of JSCeal's Compiled V8

Check Point Research publishes a static deobfuscation pipeline for JSCeal, a V8 bytecode stealer targeting crypto apps since March 2024.

3 min readJSCeal
Microsoft Teams chat interface showing an external identity warning prompt, illustrating the vishing attack vector used in the Spring Ring campaign.HIGH
Malware

Spring Ring Vishing Campaign Targets Microsoft Teams Users

Spring Ring vishing hit 150+ employees across 10 firms via Microsoft Teams, pushing RMM tools and NTLM relay attacks against domain controllers.

4 min readSpring Ring
Diagram of ValleyRAT infection chain via adware installerHIGH
Malware

ValleyRAT Backdoor Disguised as Adware Hits Windows Users

Kaspersky found ValleyRAT delivered via fake adware installer that disables Defender and sideloads libcef.dll. Targets Chinese-speaking users.

6 min readValleyRAT
ownCloud login screen with a warning overlay about CVE-2023-49105CRITICAL
Vulnerabilities

CVE-2023-49105: ownCloud Flaw Exploited to Steal Nuclear Research Data

CVE-2023-49105 (CVSS 9.8) added to CISA KEV after Chinese-speaking actor exploited it to steal nuclear research records from a Philippine agency. Patch now.

CVE-2023-49105
3 min readChinese-speaking threat actor
Screenshot of an open directory listing showing Moobot source code files and DDoS toolkit binariesHIGH
Malware

Open Directory Exposes Moobot Source Code, Active DDoS Toolkits

Censys found Moobot source code and live DDoS tools on an open directory (86.53.111[.]212) in July 2026, months after the 2024 court-authorized disruption.

4 min readMoobot
Boston Scientific corporate signage outside a buildingHIGH
Industry News

Boston Scientific Cyberattack Disrupts Medical Device Shipments

Boston Scientific disclosed a cyberattack disrupting order processing and shipments of pacemakers and stents.

3 min read
Gitea repository interface with a red alert banner indicating a critical vulnerabilityCRITICAL
Vulnerabilities

CVE-2026-60004 Gitea RCE Exploited in the Wild, CISA Warns

CVE-2026-60004, a 9.8-CVSS Gitea RCE, is under active attack per CISA. Attackers with repo write access can run shell commands. Patch now.

CVE-2026-60004
4 min read
Code snippet from the ERMAC source leak showing the constant that toggles between ERMAC and HookBot brandingHIGH
Malware

ERMAC Source Leak Reveals HookBot's Shared Core

Censys analysis of the ERMAC source leak shows HookBot and ERMAC share a codebase—one constant decides which name the panel displays. Defenders can now fingerprint both.

4 min readERMAC
Illustration of a car dashboard with a hidden malware symbolHIGH
Malware

Android Car Head Unit Malware Builds Proxy Botnet

Kaspersky found new Android malware spreading via DoFun head unit updaters, turning cars into proxy botnet nodes. First documented case on automotive head units.

4 min readMoYu Group
Page 1 of 42Next →