Security Affairs
CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers|AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign|Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106|Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION|Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits|OpenSSL Fixes HollowByte Memory Exhaustion Bug|Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network|U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog|Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets|A cyberattack hit Nichirei, one of Japan’s largest food companies|New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT|CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers|AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign|Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106|Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION|Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits|OpenSSL Fixes HollowByte Memory Exhaustion Bug|Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network|U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog|Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets|A cyberattack hit Nichirei, one of Japan’s largest food companies|New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots       AsyncAPI npm organization compromised, 2M weekly downloads affected   OkoBot: new sophisticated malware framework targets cryptocurrency users  […]

Security Affairs malware newsletter 2

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

CrashStealer: C++ macOS infostealer posing as crash reporter

Lucide Proxy: Turning Student Web Proxies into DDoS Bots      

AsyncAPI npm organization compromised, 2M weekly downloads affected  

OkoBot: new sophisticated malware framework targets cryptocurrency users 

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development  

Claude for-Chrome Extension-Bypass

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign  

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains  

ClickLock Stealer turns a locked screen into a forensics case  

Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware

Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor      

New North Korean campaign uses fake coding interviews to steal developer credentials  

NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era  

Sequel to ChainVeil npm Malware Targets Vite Ecosystem 

Symmetric Dual-Domain Prototype Adaptation for Few-Shot Image-Based Malware Classification

A Blockchain and Federated Learning Framework for Image-Based IoT Malware Detection and Prevention

A Measurement Study of AI-Environment Realism Gaps in Malware-Analysis Sandboxes

Malaika: Understanding Malware through Tri-Grounded Agentic Reasoning

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)