TeamPCP worm exploits cloud infrastructure to build criminal infrastructure

Cybersecurity researchers warned of a “massive campaign” that systematically targets cloud-native environments and sets up malicious infrastructure for subsequent exploitation. The activity, observed around December 25, 2025 and described as “worm-driven,” leveraged the recently disclosed React2Shell (CVE-2025-55182, CVSS score: 10.0) vulnerability, as well as exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers. This […]

BeyondTrust fixes critical pre-authentication RCE vulnerability in remote support and PRA

Ravi LakshmananFebruary 9, 2026Enterprise Security/Network Security BeyondTrust has released an update that addresses a critical security flaw affecting its Remote Support (RS) and Privileged Remote Access (PRA) products. Successful exploitation could lead to remote code execution. “Certain older versions of BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) contain a critical pre-authentication remote code […]

OpenClaw integrates VirusTotal scanning to detect malicious ClawHub skills

OpenClaw (formerly Moltbot and Clawdbot) announced that it is partnering with Google-owned VirusTotal to scan skills uploaded to ClawHub, a skills marketplace, as part of a broader effort to strengthen the security of its agent ecosystem. “All skills published to ClawHub are now scanned using VirusTotal’s threat intelligence, including our new Code Insight feature,” said […]

China-linked DKnife AitM framework, routers targeted for traffic hijacking and malware distribution

Rabi LakshmananFebruary 6, 2026Malware/IoT Security Cybersecurity researchers have uncovered the secrets of a gateway monitoring and attacker-in-the-man (AitM) framework called DKnife, which has been operated by Chinese-linked attackers since at least 2019. The framework consists of seven Linux-based implants designed to perform deep packet inspection, manipulate traffic, and deliver malware through routers and edge devices. […]

CISA orders removal of unsupported edge devices to reduce risk to federal networks

Rabi LakshmananFebruary 6, 2026Federal Security/Infrastructure Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal civilian executive branch (FCEB) agencies to strengthen asset lifecycle management of edge network devices and remove devices that no longer receive security updates from original equipment manufacturers (OEMs) within the next 12 to 18 months. The agency said […]

Asian State Assistance Group TGR-STA-1030 breaches 70 governments and infrastructure-related organizations

Rabi LakshmananFebruary 6, 2026Cyber ​​espionage/malware New research from Palo Alto Networks Unit 42 reveals that a previously undocumented cyber espionage group based in Asia has infiltrated the networks of at least 70 governments and critical infrastructure organizations in 37 countries over the past year. Additionally, Hacking Team was observed conducting active reconnaissance on government infrastructure […]

How Samsung Knox prevents network security breaches

As you know, enterprise network security has evolved significantly over the past decade. Firewalls have become more intelligent, threat detection methods have advanced, and access controls have become more granular. However (and this is a big “however”), the increased use of mobile devices in business operations requires network security measures specifically tailored to the unique […]

Compromised dYdX npm and PyPI packages deliver wallet stealer and RAT malware

Cybersecurity researchers have discovered a new supply chain attack that compromises legitimate packages on npm and the Python Package Index (PyPI) repository, pushing malicious versions to facilitate wallet credential theft and remote code execution. The compromised versions of the two packages are shown below. “The @dydxprotocol/v4-client-js (npm) and dydx-v4-client (PyPI) packages provide tools for developers […]