A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. Researchers found the malware…
MacSync is a relatively young, rapidly evolving family of crypto/info stealers. First advertised on the dark web in 2025 as Mac.c, the stealer was later renamed to MacSync by its creators. The…
arXiv:2609.27422v1 Announce Type: new Abstract: Deep learning-based malware detectors are commonly updated by fine-tuning on newly collected samples, but this practical update pipeline also creates…
Threat Intelligence, Threat Walkthroughs CARBONATO: a botnet built around an AI agent ThreatDown researchers uncovered CARBONATO, a Docker botnet built around an AI agent that compromises exposed…
arXiv:2609.25579v1 Announce Type: new Abstract: Backdoor repair aims to suppress malicious behavior in compromised models while preserving benign task performance. Existing studies typically evaluate…
Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.” Increasingly, AI assistants are changing from tools that simply answer questions into agents that…
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US…
Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept…
arXiv:2609.22510v1 Announce Type: new Abstract: As LLM applications integrate with external tools, they are increasingly exposed to indirect prompt injection (IPI), where adversarial instructions are…
arXiv:2609.22711v1 Announce Type: new Abstract: Offline reinforcement learning (offline RL) enables policy learning from pre-collected static datasets without online exploration, and is increasingly…
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor…
Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited…
arXiv:2609.21515v1 Announce Type: new Abstract: Third-party adapters for open-weight language models ship as opaque weight matrices; a recipient cannot check whether an adapter hides a backdoor…
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click…
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly…
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India…
China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August…
EtherHiding Exposed: Inside a Blockchain-powered Malware Campaign Hiding in Plain Sight September 17, 2026 Jean-Pierre Mouton BLOG 15 min. This is our deep dive into how we tracked cybercriminals…