US sanctions 10 over ATM malware scheme tied to Tren de Aragua
Automakers routinely share personally identifiable connected-car data with third parties, report says
Russian state hackers use new RedFlick technique to push malware
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor.
[Phishing Kit] 'Israel' Outlook Web App credentials stealer
An analysis of a phishing kit found with StalkPhish tool. This phishing kit impersonating a professional Outlook login pattern and exfiltrate credentials on an online portal (FormBuddy)... with no success.
How phishing kits uses Telegram
More and more actors uses Telegram chat groups to exfiltrate harvested data, we'll show you how we can collect informations about those actors. Let’s have a dive into one of this kits.
Phishing kit using Google sheet to exfiltrate stolen data
Analysis of a Facebook phishing kit which exfiltrate stolen data to an online Google Sheet using ajax POST method.
[Phishing kit] Scammer vs Scammer - backdoored phishing kit
Scammer world should be a hard thug life. A merciless world... with no pity... Some scammers try to steal other ones! What a shameless! During our researches we found one of those 'backdoored' phishing kit, let's have a fast dive into it.
How-to use StalkPhish.io
StalkPhish.io is a SaaS application which provides enriched data about potential phishing URL or brand impersonation use, with a REST API.
[Use case] Using Phishing-Kit-Yara-Rules project for phishing kits detection and triage
Since some months now, we maintain specific Yara rules to detect phishing kit sources (.zip files). Phishing kits sources are sometimes left on the host…
Several domain names, one protected redirector, one phishing campaign
Using PhishingKit-Yara-Rules with ClamAV
As a reminder, the PhishingKit-Yara-Rules project is a free and open source project which provides several dozen phishing kit detection rules contained in zip…
[Phishing kit] 'Moha' kit, targeting DEWA suppliers
At StalkPhish we like dissecting Phishing kits, first because we create Yara rules for detection, secondly because we must continually keep up to date with new…
[Phishing kit] M&T Bank - Telegram exfiltration kit, without any Telegram link
One of the latest kits downloaded by StalkPhish targets customers of the online bank M&T. It has a special feature that we wanted to share with you. We still…
DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.
After reports on suicide deaths, Pentagon puts Cyber Command on notice
Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data.
Agenti AI, il rischio è nel perimetro: cosa insegnano gli ultimi incidenti
Dalla fuga dalla sandbox al blocco di GPT-6.1 Astra, fra agosto e settembre si sono moltiplicati gli incidenti cyber. Ecco perché i casi degli Agenti AI di OpenAI e Anthropic costringono a spostare l’attenzione dal comportamento anomalo dei singoli modelli all'affidabilità del perimetro di training del modello
Flash Notice: Brand Impersonation & App-Store Fraud: GTA 6: Unreleased Title Hype-Jacking
Discover PreCrime Labs' threat intelligence report on 16 unauthorized GTA 6 mobile apps on Google Play executing brand impersonation and financial scam risks.
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.
Oxygen Forensics, il caso USA riapre il rischio supply chain nel software critico
Il sequestro dell’infrastruttura di Oxygen Forensics non nasce, allo stato, da una compromissione tecnica del software, ma dalle contestazioni sulla proprietà societaria e sulla provenienza dello sviluppo. Il caso mostra perché supply chain, vendor risk e continuità operativa sono ormai parte della sicurezza delle tecnologie critiche
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.
RemusStealer: EtherHiding In Hidden Windows
LummaStealer is a notorious information stealer active since at least 2022 and has been covered in a previous Binary Defense blog post regarding ClickFix initial access methods, which can be f ound here. In contrast, one key difference between LummaStealer and RemusStealer in recent campaigns is that, instead of utilizing Steam or Telegram as a dead drop resolver, RemusStealer is observed to employ Ethereum smart contracts to facilitate C2 communications. Dynamic analysis within the Binary Defense malware lab revealed that recent samples of RemusStealer will attempt to reach out to eth[.]llamarpc[.]com, which is associated with Ethereum. Infection Timeline & Analysis Initial static analysis of RemusStealer revealed that the payload is written in Go, with functionality consistent of discovery tactics via the following: -GetSystemInfo -GetSystemDirectoryA When executed, the payload performed system discovery via the following: -SELECT * FROM AntiVirusProduct -SELECT * FROM Win32_VideoController -SELECT * FROM Win32_OperatingSystem These commands gather information regarding the compromised system’s operating system, detailed information on hardware specifications, settings and status information in relation to graphics/display adapters, and the current installed antivirus product. Hidden Desktops RemusStealer is observed to employ the use of hidden/alternative desktops as a means to evade detection on the compromised machine by the victim.
Mobile malware warning from Ukrainian researchers includes iPhone exploit kit
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls.
Trump inaugura l’era della “Super Intelligence”: la sicurezza dell’AI passa alle Big Tech
Trump ribattezza l'intelligenza artificiale «Super Intelligence» con un ordine esecutivo. Ma la sostanza cyber è nell'accordo firmato dalle Big dell'AI: quattro livelli di controlli e audit, volontari e con una supervisione indipendente. Cosa prevedono, dove sono i limiti e cosa devono fare aziende e consulenti
Microsoft to block Entra ID script injection attacks starting October
Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month.
OpenAI AI Models Accessed Australian Government Systems Without Authorization
The OpenAI hack saw AI models access Australian government systems during training, prompting an investigation and stronger security measures.
TeamViewer urges users to patch severe flaws “as soon as possible”
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.
Medela - 423,947 breached accounts
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consisted primarily of corporate contact information, including names, physical addresses and phone numbers, with some records also containing associated support tickets.