JanelaRAT malware targets Latin American banks with 14,739 attacks in Brazil in 2025

Ravi LakshmananApril 13, 2026Threat Intelligence/Malware Banks and financial institutions in Latin American countries such as Brazil and Mexico continue to be targeted by a malware family called JanelaRAT. JanelaRAT, a modified version of BX RAT, is known to track mouse inputs, log keystrokes, take screenshots, and collect system metadata, as well as steal financial and […]
FBI and Indonesian police dismantle W3LL phishing network behind $20 million fraud

Ravi LakshmananApril 13, 2026Cybercrime/Threat Intelligence The U.S. Federal Bureau of Investigation (FBI), in collaboration with the Indonesian National Police, has dismantled the infrastructure associated with a global phishing operation that utilized an off-the-shelf toolkit called W3LL to steal the account credentials of thousands of victims and attempt to defraud more than $20 million. In parallel, […]
Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More

Ravie LakshmananApr 13, 2026Cybersecurity / Hacking Monday is back, and the weekend’s backlog of chaos is officially hitting the fan. We are tracking a critical zero-day that has been quietly living in your PDFs for months, plus some aggressive state-sponsored meddling in infrastructure that is finally coming to light. It is one of those mornings where the gap […]
MTTD looks great. No gaps after alert

Last week, Anthropic restricted its Mythos preview model following the autonomous discovery and exploitation of zero-day vulnerabilities across all major operating systems and browsers. Palo Alto Networks’ Wendy Whitmore warned that it could take weeks or months for similar features to become widespread. According to CrowdStrike’s 2026 Global Threat Report, the average breakout time for […]
North Korea’s APT37 uses Facebook social engineering to deliver RokRAT malware

Ravi LakshmananApril 13, 2026Social engineering/threat intelligence A North Korean hacker group tracked as APT37 (also known as ScarCruft) is believed to be involved in a new multi-stage social engineering campaign. In this campaign, threat actors approached targets on Facebook and added them as friends on the social media platform, turning the trust-building exercise into a […]
OpenAI revokes macOS app certificates following malicious Axios supply chain incident

OpenAI disclosed a GitHub Actions workflow used to sign a macOS app that downloaded the malicious Axios library on March 31, but noted that no user data or internal systems were compromised. “Out of an abundance of caution, we are taking steps to protect the process by which our macOS applications certify that they are […]
Cloud Threat Retrospective 2026 | Wiz Research

Traditional vulnerabilities remain a key factor in cloud threat actor activity in 2025. In publicly documented incidents in Wiz’s cloud threat landscape, most initial accesses involved weaponized vulnerabilities, exposed secrets, and misconfigurations. However, the well-known nature of these vectors should not be misinterpreted to mean that the impact of an attacker’s actions will be limited […]
CPUID Compromise Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads

Rabi LakshmananApril 12, 2026Malware/Threat Intelligence An unknown attacker has compromised CPUID (‘cpuid[.]com”), a website that hosts popular hardware monitoring tools such as CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor, served a malicious executable of software and deployed a remote access Trojan called STX RAT within 24 hours. The incident lasted from approximately 15:00 UTC on April […]
Adobe patches actively exploited Acrobat Reader flaw CVE-2026-34621

Rabi LakshmananApril 12, 2026Vulnerabilities / Endpoint Security Adobe has released an emergency update to fix a critical security flaw in Acrobat Reader that is being exploited in the wild. This vulnerability has been assigned the CVE identifier CVE-2026-34621 and has a CVSS score of 9.6 out of 10.0. Successful exploitation of this flaw could allow […]
Law enforcement uses Webloc to track 500 million devices via advertising data

Hungary’s domestic intelligence agency, El Salvador’s national police, and several law enforcement agencies and police departments in the United States are believed to have used an ad-based global geolocation surveillance system called Weblock. According to a report published by Citizen Lab, the tool was developed by Israeli company Cobwebs Technologies and sold by its successor, […]