Arsink is a cloud-native Android RAT that exfiltrates extensive personal data and grants remote operators intrusive control over infected devices while abusing legitimate cloud services for C2 and media/file exfiltration. The campaign deployed 1,216 distinct APKs across global social-engineered distribution channels and used 317 Firebase Realtime Database endpoints, Google Apps Script/Drive, and Telegram for C2 and exfiltration. #Arsink #Firebase

Read More
Aisuru botnet sets new record with 31.4 Tbps DDoS attack

The Aisuru/Kimwolf botnet launched a record-breaking DDoS campaign that peaked at 31.4 Tbps and generated over 200 million HTTP requests per second, targeting telecommunications providers, IT organizations, and Cloudflare’s dashboard and infrastructure. Cloudflare reported it detected and automatically mitigated the attacks on December 19 and noted a 121% year-over-year increase in…

Read More
Ransom! all Data (JAN-2026)

The claim attributes the ransomware to the tengu group and the Tahkout Group, citing targets such as skyegtours.com, KSP TLM, COMPAGNIE FONCIÈRE PARISIENNE, lenotech.com.ph, Jakarta, Nanyang School, and namico.go.ke, with all data reportedly compromised. The claim implies encryption or exfiltration of all data across these entities, with impacted country coverage including Indonesia, the Philippines, and Kenya. #Indonesia #Philippines #Kenya

Read More
Nation-State Hackers, Cybercriminals Weaponize Patched WinRAR Flaw Despite Six-Month-Old Fix

Russian and Chinese state-backed groups and financially motivated actors have been exploiting CVE-2025-8088 in WinRAR to drop malware into Windows Startup folders using a path traversal vulnerability combined with Alternate Data Streams. The flaw remained widely abused months after RARLAB released WinRAR 7.13, with actors like UNC4895 (RomCom), APT44 (FROZENBARENTS), Turla,…

Read More
Malicious Open Source Software Packages Neared 500,000 in 2025

Malicious open source packages surged into industrialized, large-scale campaigns in 2025, with researchers identifying more than 454,600 new malicious packages across npm, PyPI, Maven Central, NuGet, and Hugging Face and attacks increasing in sophistication. The report spotlights npm as the primary vector—featuring self-replicating packages like Shai-Hulud, activity from threat actors such…

Read More
Cybercriminals and nation-state groups are exploiting a six-month old WinRAR defect

Google’s Threat Intelligence Group warns that a path-traversal flaw in WinRAR (CVE-2025-8088) disclosed and patched six months ago is still being actively exploited by a diverse set of attackers. Nation-state actors linked to Russia and China and financially motivated cybercriminals have been deploying silent, no-interaction payloads into critical locations like the…

Read More
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088

The GTIG reported widespread exploitation of CVE-2025-8088 in WinRAR using Alternate Data Streams and path traversal to drop payloads into the Windows Startup folder for persistence across state-sponsored and financially motivated campaigns. Defenders are urged to patch immediately and hunt for indicators such as malicious RAR archives, LNK/HTA/BAT/CMD payloads, and the provided SHA-256 hashes. #CVE-2025-8088 #WinRAR

Read More