APT36 and SideCopy launch cross-platform RAT campaign against Indian companies

Ravi LakshmananFebruary 11, 2026Cyber espionage/threat intelligence India’s defense sector and government-linked organizations have been targeted by multiple campaigns aimed at compromising Windows and Linux environments using remote access Trojans that can steal sensitive data and ensure continued access to infected machines. This campaign is characterized by the use of malware families such as Geta RAT, […]
Public training opens the door to crypto mining in Fortune 500 cloud environments

hacker newsFebruary 11, 2026Identity Security/Threat Exposure Deliberately vulnerable training applications are widely used for security education, internal testing, and product demonstrations. Tools like OWASP Juice Shop, DVWA, Hackazon, and bWAPP are designed to be insecure by default, so it helps to learn how common attack techniques work in a controlled environment. The problem is not […]
Microsoft patches 59 vulnerabilities, including 6 actively exploited zero-days

Microsoft on Tuesday released a security update that addresses 59 flaws across its software. This includes six vulnerabilities that are said to have been actually exploited. Of the 59 deficiencies, 5 are rated as ‘severe’, 52 are rated as ‘important’, and 2 are rated as ‘moderate’ severity. 25 of the patched vulnerabilities are classified as […]
SSHStalker botnet uses IRC C2 to control Linux systems via legacy kernel exploits

Ravi LakshmananFebruary 11, 2026Linux / Botnet Cybersecurity researchers have revealed details of a new botnet operation called SSHStalker that relies on the Internet Relay Chat (IRC) communication protocol for command and control (C2) purposes. “This toolset blends stealth helpers with legacy-era Linux exploits. Alongside log cleaners (utmp/wtmp/lastlog tampering) and rootkit-class artifacts, attackers maintain a large […]
North Korea-linked UNC1069 uses AI decoys to attack crypto organizations

A North Korea-related threat actor known as UNC1069 has been observed targeting the cryptocurrency sector to steal sensitive data from Windows and macOS systems, with the ultimate goal of facilitating financial theft. Google Mandiant researchers Ross Inman and Adrian Hernandez said, “This intrusion relied on social engineering schemes including compromised Telegram accounts, fake Zoom meetings, […]
North Korean agents impersonate experts on LinkedIn to infiltrate companies

Information technology (IT) employees associated with the Democratic People’s Republic of Korea (DPRK) are now applying for remote jobs using the real LinkedIn accounts of impersonated individuals, marking a new expansion of fraud. “These profiles often include verified work emails and ID badges, which North Korean operatives hope will make fraudulent applications appear legitimate,” the […]
Reynolds ransomware embeds BYOVD drivers that disable EDR security tools

Cybersecurity researchers have revealed details about an emerging ransomware family called Reynolds. This family includes a Bring Your Own Vulnerable Driver (BYOVD) component in the ransomware payload itself to evade defenses. BYOVD refers to an adversarial technique that exploits legitimate but flawed driver software to escalate privileges and disable endpoint detection and response (EDR) solutions, […]
Inside the rise of the digital parasite

Are ransomware and encryption still the defining signs of modern cyberattacks, or has the industry become so focused on the noise that it has missed the more dangerous changes happening quietly around it? According to Picus Labs’ new Red Report 2026, which analyzed more than 1.1 million malicious files and mapped 15.5 million hostile acts […]
ZAST.AI raises $6M in Pre-A to scale AI-powered code security with “zero false positives”

hacker newsFebruary 10, 2026Application security/artificial intelligence Seattle, USA, January 5, 2026 — ZAST.AI announces the completion of a $6 million Pre-A funding round. The investment comes from well-known investment firm Hillhouse Capital and brings ZAST.AI’s total funding to nearly $10 million. This marks recognition from major capital markets for a new solution that ends the […]
Warlock ransomware infiltrates SmarterTools through unpatched SmarterMail servers

Last week, SmarterTools confirmed that the Warlock (aka Storm-2603) ransomware group exploited unpatched SmarterMail instances to infiltrate networks. Derek Curtis, the company’s chief commercial officer, said the incident occurred on January 29, 2026, when an email server that had not been updated to the latest version was compromised. “Prior to the breach, we had approximately […]