Malware
Researchers discover SSHStalker botnet infecting Linux servers
Ti AI ṣe iroyin Àwòrán tí AI ṣe
Flare researchers have identified a new Linux botnet called SSHStalker that has compromised around 7,000 systems using outdated exploits and SSH scanning. The botnet employs IRC for command-and-control while maintaining dormant persistence without immediate malicious activities like DDoS or cryptomining. It targets legacy Linux kernels, highlighting risks in neglected infrastructure.
The popular AUR helper yay released version 13 on June 18 with new tools to help users detect risky packages. The update follows multiple waves of malware that compromised over 1,500 packages in the Arch User Repository.
Ti AI ṣe iroyin
Arch Linux has disabled new account registrations for the Arch User Repository following multiple waves of malicious package updates. The move comes after more than 1,500 packages were compromised last week.
Law enforcement agencies from the United States and Europe, supported by private partners, have taken down the SocksEscort cybercrime proxy network. This service, powered by the AVRecon malware infecting Linux-based devices, provided cybercriminals with access to compromised IP addresses. The operation resulted in the seizure of domains, servers, and cryptocurrency assets.
Ti AI ṣe iroyin
Researchers at Black Lotus Labs have identified a botnet infecting around 14,000 routers daily, mostly Asus models in the US, using advanced peer-to-peer technology to evade detection. The malware, known as KadNap, turns these devices into proxies for cybercrime activities. Infected users are advised to factory reset their routers and apply firmware updates to remove the threat.
A North Korean hacking group known as UNC1069 has employed AI-generated videos to deliver malware targeting both macOS and Windows systems. This tactic highlights evolving methods in cyber threats. The development was reported by TechRadar on February 11, 2026.
Ti AI ṣe iroyin
Cyble Research and Intelligence Labs has revealed ShadowHS, a sophisticated fileless framework for post-exploitation on Linux systems. The tool enables stealthy, in-memory operations and long-term access for attackers. It features a weaponized version of hackshell and advanced evasion techniques.
Malware infects 1579 packages in Arch Linux AUR
May 25, 2026 20:59Trapdoor malware targets crypto and ai developers
May 12, 2026 15:32Android malware returns disguised as TikTok or streaming apps
May 12, 2026 07:58Scammers expand Claude malware campaign to target Mac users via ads and fake support sites
May 11, 2026 06:22Fake OpenAI repository tops Hugging Face downloads
February 23, 2026 08:01Malicious npm packages harvest crypto keys and secrets
February 20, 2026 10:04Massiv android malware targets portuguese users with fake iptv app
February 19, 2026 13:36Researchers uncover new SysUpdate malware variant targeting Linux
February 18, 2026 23:37New SysUpdate malware variant targets Linux systems
February 17, 2026 10:18OpenClaw AI agents targeted by infostealer malware for first time