
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors

North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors

Attackers compromised ConnectWise ScreenConnect servers to automatically deliver malicious payloads to newly connected clients in a self-propagating campaign.

BigBear 2.0 phishing-as-a-service framework stole over 5,000 Microsoft 365 credentials from 258 organizations using adversary-in-the-middle attacks.

ConnectWise disclosed a new ScreenConnect vulnerability with no patch available. The vendor shared temporary mitigations and plans a fix this

Check Point Research discovered JSCeal malware that harvests credentials and bypasses Google authentication using stolen session cookies on Windows.

Elastic Security Labs found four REVSTEALER persistence modules that remain after the stealer deletes itself, disabling Defender to run a

Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits

METR disclosed two incidents where attackers stole API keys and consumed $600,000 in AI credits through fail-open authentication and targeted

Russian threat actor UAC-0099 deployed GuardBreaker technique, inserting safety-sensitive phrases into malware to trip AI security analysis mechanisms.

Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy following December 2025 arrests for Tren de Aragua malware operations in
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.