Endpoint Security

Cybersecurity
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
CERT-UA attributes a Sandworm-linked UAC-0145 social engineering campaign using fake job interviews and trojanized WireGuard VPN clients against Ukraine.
Cybersecurity
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
Palo Alto Unit 42 documents Kimwolf v7 using HTTP/2 C2 to mimic legitimate browsing, evade DDoS detection, and expand across Android and IoT devices worldwide.
CVE Vulnerability Alerts
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
Researcher Hyunwoo Kim documented Zapscape, CVE-2026-64561, a KVM/x86 shadow memory flaw allowing privileged L1 guest code to escape to the Linux host.
Cybersecurity
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
MIT CSAIL's interrupt injection attack named TONTOU bypasses retpoline and Safe-RET defenses on AMD Zen 2 to leak Linux password hashes from userspace.
Cybersecurity
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
Huntress discovered a Go-based macOS infostealer delivered through ClickFix attacks that steals crypto assets and redirects a percentage of each transaction.
Cybersecurity
ClickFix Malware Gate Fingerprints macOS Users Before Lures
Microsoft detailed a ClickFix campaign spanning 250 domains that fingerprints macOS visitors server-side before deciding whether to show an infostealer lure.
Application Security
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Open VSX removed 77 malicious evil-twin extensions impersonating developer tools and exfiltrating machine, Git, and CI/CD data to one attacker domain.
Application Security
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
Cybersecurity
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent access.
Application Security
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.