
Cruciferra Crypter Combines BYOVD and Process Ghosting to Kill EDR
Cruciferra, a MaaS crypter active since fall 2025, bypasses EDR via BYOVD and Process Ghosting. TA4922, Silver Fox, and 11

Cruciferra, a MaaS crypter active since fall 2025, bypasses EDR via BYOVD and Process Ghosting. TA4922, Silver Fox, and 11

BlackFog exposed MedusaHVNC, a MaaS RAT that runs browsers on a hidden Windows virtual desktop to commit banking fraud without

Zscaler ThreatLabz uncovered TELESHIM, MIXEDKEY, and BINDCLOAK — three new malware families an East Asia-linked APT used against Middle Eastern

SourTrade malvertising downloads encrypted fragments and assembles a Windows executable in browser memory, evading file-based detection across 12 countries.

Attackers target Steam discussion forums with ClickFix social engineering, tricking players into running PowerShell that installs a SYSTEM-level XMRig miner.

Group-IB documented ClickLock, a macOS stealer using a 210ms app-kill loop to coerce macOS passwords, hitting more than 100 victims

Elastic Security Labs disclosed TELEPUZ, a C-based malware distributed through a ClickFix-to-Vidar chain with VirusTotal volumes indicating a MaaS operation.

Trend Micro documented Russian actor ‘bandcampro’ using Gemini CLI as a hacking assistant in a dental clinic botnet attack on

Security group Nightmare Eclipse released LegacyHive, a PoC targeting an unpatched Windows privilege escalation flaw that survived July Patch Tuesday.

Bitdefender documented three Windows bind link techniques — file-binding, process-binding, and silo-binding — that redirect OS path resolution to hide
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.