OptinMonster CDN Backdoor Checks
WordPress sites using OptinMonster, TrustPulse, or PushEngage should check for rogue admin…
FlutterShell Backdoor on Mac: Operation FlutterBridge Cleanup Guide
FlutterShell is a macOS backdoor tied to Operation FlutterBridge. Check fake apps,…
nethost.dll ProtonVPN Cleanup
Found nethost.dll beside ProtonVPN.exe or a fake VPN folder? Learn how to…
Steam C2 Backdoor
GoDaddy says WordPress malware hides C2 data in Steam profile comments. Check…
sysupdate.jpeg Malware
sysupdate.jpeg malware is a fake image loader tied to Operation SilentCanvas. Learn…
Microsoft Details Kazuar Botnet Used by Secret Blizzard
Microsoft published a technical analysis of Kazuar, a modular Secret Blizzard botnet…
node-ipc npm Package Compromised With Credential Stealer
Malicious node-ipc versions 9.1.6, 9.2.3, and 12.0.1 were published to npm with…
cPanel CVE-2026-41940 Exploited to Drop Filemanager Backdoor
Attackers are exploiting cPanel & WHM CVE-2026-41940 to deploy a Filemanager backdoor,…
PamDOORa Linux PAM Backdoor Turns SSH Login Into a Trap
PamDOORa is a Linux PAM-based backdoor marketed for persistent OpenSSH access and…
Is JDownloader Safe?
JDownloader says attackers changed several official website download links on May 6-7,…
QLNX RAT Targets Linux Developer and Cloud Credentials
Trend Micro reports QLNX, a Linux-focused Quasar RAT variant that combines persistence,…
PyPI ZiChatBot Packages Linked to Suspected OceanLotus Campaign
Kaspersky reports a suspected OceanLotus campaign that used malicious PyPI packages to…
