Malware

Fuatilia
Dramatic server room scene illustrating the SSHStalker Linux botnet infecting thousands of vulnerable servers via SSH exploits.
Picha iliyoundwa na AI

Researchers discover SSHStalker botnet infecting Linux servers

Imeripotiwa na AI Picha iliyoundwa na AI

Flare researchers have identified a new Linux botnet called SSHStalker that has compromised around 7,000 systems using outdated exploits and SSH scanning. The botnet employs IRC for command-and-control while maintaining dormant persistence without immediate malicious activities like DDoS or cryptomining. It targets legacy Linux kernels, highlighting risks in neglected infrastructure.

The popular AUR helper yay released version 13 on June 18 with new tools to help users detect risky packages. The update follows multiple waves of malware that compromised over 1,500 packages in the Arch User Repository.

Imeripotiwa na AI

Arch Linux has disabled new account registrations for the Arch User Repository following multiple waves of malicious package updates. The move comes after more than 1,500 packages were compromised last week.

Law enforcement agencies from the United States and Europe, supported by private partners, have taken down the SocksEscort cybercrime proxy network. This service, powered by the AVRecon malware infecting Linux-based devices, provided cybercriminals with access to compromised IP addresses. The operation resulted in the seizure of domains, servers, and cryptocurrency assets.

Imeripotiwa na AI

Researchers at Black Lotus Labs have identified a botnet infecting around 14,000 routers daily, mostly Asus models in the US, using advanced peer-to-peer technology to evade detection. The malware, known as KadNap, turns these devices into proxies for cybercrime activities. Infected users are advised to factory reset their routers and apply firmware updates to remove the threat.

A North Korean hacking group known as UNC1069 has employed AI-generated videos to deliver malware targeting both macOS and Windows systems. This tactic highlights evolving methods in cyber threats. The development was reported by TechRadar on February 11, 2026.

Imeripotiwa na AI

Cyble Research and Intelligence Labs has revealed ShadowHS, a sophisticated fileless framework for post-exploitation on Linux systems. The tool enables stealthy, in-memory operations and long-term access for attackers. It features a weaponized version of hackshell and advanced evasion techniques.

Jumamosi, 13. Mwezi wa sita 2026, 16:49:43

Malware infects 1579 packages in Arch Linux AUR

Jumatatu, 25. Mwezi wa tano 2026, 20:59:52

Trapdoor malware targets crypto and ai developers

Jumanne, 12. Mwezi wa tano 2026, 15:32:17

Android malware returns disguised as TikTok or streaming apps

Jumanne, 12. Mwezi wa tano 2026, 07:58:04

Scammers expand Claude malware campaign to target Mac users via ads and fake support sites

Jumatatu, 11. Mwezi wa tano 2026, 06:22:56

Fake OpenAI repository tops Hugging Face downloads

Jumatatu, 23. Mwezi wa pili 2026, 08:01:15

Malicious npm packages harvest crypto keys and secrets

Ijumaa, 20. Mwezi wa pili 2026, 10:04:38

Massiv android malware targets portuguese users with fake iptv app

Alhamisi, 19. Mwezi wa pili 2026, 13:36:25

Researchers uncover new SysUpdate malware variant targeting Linux

Jumatano, 18. Mwezi wa pili 2026, 23:37:21

New SysUpdate malware variant targets Linux systems

Jumanne, 17. Mwezi wa pili 2026, 10:18:59

OpenClaw AI agents targeted by infostealer malware for first time

 

 

 

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa