EvilBit Threat Digest - Records Fall, Firewalls Fall Harder, and the Robot Intern Keeps Wandering Off
The OpenAI and Hugging Face agent swarm, a record 974-CVE Patch Tuesday, and an actively exploited CVSS 10.0 in Cisco Secure FMC.
| Spotlight | Article | Details |
|---|---|---|
| Latest | EvilBit Threat Digest - Records Fall, Firewalls Fall Harder, and the Robot Intern Keeps Wandering OffThe OpenAI and Hugging Face agent swarm, a record 974-CVE Patch Tuesday, and an actively exploited CVSS 10.0 in Cisco Secure FMC. aiagentsvulnerabilitiespatchesidentity+2 more | |
| Featured | EvilBit Threat Digest - Blackouts, Backdoors, and Browser BrainwormsKryptoKat A cross-cutting security digest on geopolitics shaping outages, new APT chains, AI prompt risks, cryptomining, and pragmatic patching guidance. geopoliticsaptiran | |
| Date | Article | Details |
|---|---|---|
Examines IoT botnets, kernel LPEs, and Pwn2Own Berlin to show how chained primitives across devices and AI tooling expand the attack surface. iot adb mirai lpes kernel+2 more | ||
| Date | Article | Details |
|---|---|---|
Cisco SD-WAN CVSS 10.0 under active exploit, May Patch Tuesday brings a wormable Windows DNS Client RCE, and the npm worm reaches OpenAI. ciscosd-wancve-2026-20182patch-tuesdaysupply-chain+3 more | ||
Apple's May patch bomb hits every OS, Mini Shai-Hulud poisons 170 npm packages, and DPRK laptop-farm enablers each catch 18 months. apple security patches kernel sandbox+2 more | ||
| Date | Article | Details |
|---|---|---|
Copy Fail kernel LPE traverses containers, Microsoft AiTM hits 35,000 users, cPanel auth bypass on KEV, and three federal sentencings. phishing infrastructure patches ransomware supply-chain+2 more | ||
Dual-RMM phishing hits 80+ orgs, cPanel and MOVEit auth bypasses under active exploit, APT28 keeps hijacking routers for M365 token theft. | ||
| Date | Article | Details |
|---|---|---|
BlackCat insiders draw 4-year sentences, ShinyHunters AI-vishes ADT and Medtronic, and Mini Shai-Hulud worms its way into more npm packages. supply-chain npm pypi insider ransomware+2 more | ||
Patch volume was up this week. The louder stories came from attackers abusing trust at the edges of developer workflows, AI tooling, and government portals. patch-tuesday supply-chain backdoor npm bitwarden+2 more | ||
| Date | Article | Details |
|---|---|---|
Preloaded LunaSpy phones, in-memory ScreenConnect drops, npm typosquats stealing SSH keys, two Cisco ISE 9.9s. Disk is for chumps this week. lunaspy preinstalled hardware fileless rmm+2 more | ||
Nightmare-Eclipse Defender LPEs land in real intrusions, four Android bankers share 800+ targets, and Claude helps hijack BuddyBoss WordPress. nightmare-eclipse android-bankers vpn supply-chain chrome-extension+2 more | ||
| Date | Article | Details |
|---|---|---|
Developers lured through Slack, macOS users tricked into pasting malware, AI prompt injection in government, and NHS domains hijacked. trust cybersecurity supplychain macos phishing+2 more | ||
Kimsuky's credential playbook, Docker API miners, SystemBC's ransomware empire, RomCom zero-day chains, and why your extensions are someone else's red team. kimsuky docker lnk c2 powershell+2 more | ||
Operational trust abused at machine speed: Axios, prt-scan, EvilTokens, Storm-1175, PolyShell, ComfyUI. Features, until they're evidence. axiosprt-scaneviltokensstorm1175polyshell+1 more | ||
| Date | Article | Details |
|---|---|---|
Supply chain compromises dominate the week: axios attribution lands, CI/CD blast radius widens, and phishing kits shrug off takedowns. supply-chain npm pypi rubygems browser-extensions+2 more | ||
TeamPCP supply-chain attacks hit PyPI and npm, GlassWorm returns with unkillable Solana C2, and new fileless primitives ForsHops and FlipSwitch raise the stealth bar. supply-chain backdoors pypi npm ide-extensions+1 more | ||
Active RCE in F5 BIG-IP APM, a nation-state npm supply-chain compromise, and macOS ClickFix stealer. April 1, but none of this is a joke. f5-big-iprcecve-2025-53521axiosnpm+3 more | ||
| Date | Article | Details |
|---|---|---|
There is a particular kind of exhaustion that comes from watching the same trust model break in five different ways before Friday. CI/CD credentials as skeleton keys, a Python runtime weaponized for ambient persistence, and phishing that sounds like bureaucracy. supply-chain ci-cd magecart rootkits ebpf | ||
Supply chain cascades, blockchain C2, browser encryption bypasses, and 20-hour exploit weaponization. UncleSp1d3r breaks down the chains. supply-chainmalwarenpmtyposquattingc2+1 more | ||
Wipers riding Kubernetes, supply chains turned inside out, and "trusted" platforms doing the con's heavy lifting. This week's threats hide where you already look. kubernetes wipers supply-chain lite-llm github+1 more | ||
| Date | Article | Details |
|---|---|---|
Trust failures defined the week: poisoned CI tags, stealthy C2, real-time phishing theft, and patch priorities defenders cannot ignore. supply-chainc2phishingmalwareendpoints+1 more | ||
Process hollowing, Deno signing abuse, build-time supply chain poisoning, and AOT evasion: this week's techniques dissected for operators. supply-chainruntimedenodotnetaot | ||
Weekly digest of self-propagating supply-chain worms, credential pivots into cloud data, and social engineering driving trust abuse in vendors …and it’s only halfway over. supply-chain worms credentials cloud social-engineering+2 more | ||
| Date | Article | Details |
|---|---|---|
A summary of threats abusing identity and cloud admin tools to weaponize admin consoles, with supply-chain and phishing trends. admin-console cloud identity rmm phishing+1 more | ||
A snapshot of rising cyber threats: blockchain-backed C2, fileless runtimes, IoT botnets, and state-sponsored intrusions shaping modern operations. blockchain c2 fileless iot botnet+1 more | ||
Weekly threat digest on how free trials, copy/paste install guides, and trusted tech boundaries are weaponized, with actionable defenses. macos ios phishing extensions cloud | ||
| Date | Article | Details |
|---|---|---|
Threat digest on Rust-based backdoors, phishing-kit takedowns, SSL graph-based threat hunting, AI prompt-injection exploits, and Cisco advisories. rust deno backdoors phishing ai+2 more | ||
A red-team roundup of chaining zero-days, browser rats, air-gap hops, and evasive phishing techniques for stealthy ops. zero-daysratsphishingevasionbackdoor+2 more | ||
| Date | Article | Details |
|---|---|---|
Cloud-first malware roundup: GRIDTIDE uses Google Sheets as C2, PlugX evolutions, React RCE, SeaFlower wallet clones, fixes. gridtidegoogle-sheetsplugxseaflowercve-2025-55182+2 more | ||
Poisoned npm packages hijack AI dev tools, MIMICRAT laughs at ETW, and a Cisco zero-day's been burning since 2023. Sharpen up. supply-chain npm nuget sandworm-mode jit-hooking+2 more | ||
Midweek threat digest on AI-agent skill abuse, deepfake social engineering, ransomware links, Office bugs, mobile banking threats, and attack surface. ai-agent deepfake macos ransomware office+2 more | ||
| Date | Article | Details |
|---|---|---|
Weekly security recap on AI-driven deception, BYOVD, steganography, and crypto-enabled infostealers shaping last month's threats. aihoneypotsinfostealersbyovdsteganography+1 more | ||
Proxy malware is getting trickier, supply chains are still a dumpster fire, zero-days keep landing, loaders are mutating, and now we've got AI poisoning to worry about. Here's what's actually worth your time this week. proxy malware zeroday supplychain ai-poisoning+2 more | ||
Attackers leaned on other people's infrastructure this week: OAST callback services, SaaS notifications, AI/extension marketplaces, fake installers, and a very convincing lookalike 7-Zip site all did their part to make defenders question reality and make incident responders question coffee. | ||
Threat digest on attackers abusing trusted platforms like OAST, SaaS notifications, fake installers, and extension markets to turn user trust into an expanding attack surface. oast saas proxyware cve-2026-1281 dll-sideloading+2 more | ||
Threat actors abuse legitimate platforms and invitation-based access, turning hosts into attack surfaces. oast threat-intel cloud-security phishing supply-chain+1 more | ||
| Date | Article | Details |
|---|---|---|
Weekly briefing on how attackers abuse trust layers such as package registries, QR codes, AI platforms, and search ads to breach supply chains. supply-chain qr-codes ai malware phishing+2 more | ||
Weekly briefing on AI-driven evasion, deepfake malware, cloud C2s, and smishing that bypasses 2FA, with defender-focused mitigations. aievasionsmishingc2apt28+2 more | ||
Your midweek security digest covers deceptive traffic origins, malicious installers, and trusted delivery channels that threaten credentials and endpoints. traffic-origin phishing endpoint supply-chain fake-stores+1 more | ||
| Date | Article | Details |
|---|---|---|
Threat digest on DNS as control plane via compromised routers and shadow resolvers, weak admin interfaces, evolving scams, and AI-enabled risk. dns edge-routers shadow-resolvers tds admin-ui+2 more | ||
Explores firmware and extension-era attack chains - from UEFI boot-service hooks to Android/Windows RATs, NFC data exfil, and supply-chain risks. uefi firmware rat nfc supplychain+2 more | ||
A digest of threats from weaponized RTFs and rogue editor extensions, plus credential-stealing campaigns, supply-chain abuses, and defender tips. rtfofficeapt28cve-2026-21509glassworm+2 more | ||
| Date | Article | Details |
|---|---|---|
Threat digest on attackers abusing trusted services—from update servers to cloud mail—turning trust into a weapon and evading detection. supply-chain phishing cloud malware trust+1 more | ||
Threat digest on attackers abusing trusted services - from update servers to cloud mail - turning trust into a weapon and evading detection. supply-chain phishing cloud malware trust+1 more | ||
Your compliance dashboard is green. Your patching metrics satisfy the auditors. The attackers are still inside. security tools threats patching ide+1 more | ||
Threat actors weaponize infrastructure at scale, from wipers targeting power grids to supply-chain malware and browser extensions that act as C2. infrastructure threats phishing supply-chain npm+1 more | ||
| Date | Article | Details |
|---|---|---|
Roundup: LastPass phishing, ErrTraffic ClickFix, BlueNoroff macOS/supply-chain attacks, MCP AI-agent risks, and WordPress/mJobtime exploits. phishingai-agentsmalwaresupply-chainmacos+1 more | ||
Fortinet firewalls compromised despite patches, malicious VS Code AI extensions steal code from 1.5M developers, and phishing kits exploit trusted cloud platforms. fortinetvscodephishingvulnerabilitymalware+3 more | ||
VoidLink malware compiles custom kernel rootkits on-demand, plus critical n8n and WordPress vulnerabilities, DLL side-loading campaigns, and more threats analyzed. voidlinkrootkitlinuxcloud-securitymalware+3 more | ||
| Date | Article | Details |
|---|---|---|
Critical RCE flaws in Sitecore, HPE OneView, and Magento face active exploitation. Plus: OAuth phishing tricks, RMM tool abuse, and new cloud-native Linux malware. deserializationrcemagentositecoremalware+3 more | ||
Weekly analysis of evasion and OPSEC failures: hardware-breakpoint AMSI bypass, unstripped Rust build paths ('Jacob'), cloud-native VoidLink, and markdown exfil. malwareevasionopsecrustcloud-native+1 more | ||
Attackers weaponize trust with HTML QR phishing, multi-stage AsyncRAT, fake Fortinet VPNs, OAST campaigns, LLM SSRF, SSH and RMM abuse. phishingasyncratllm-securityseo-poisoningssh+3 more | ||
| Date | Article | Details |
|---|---|---|
Knownsec leak exposes Chinese cyber-espionage tools, npm supply-chain attacks use blockchain C2, malicious Chrome extensions steal AI chats, and WhatsApp becomes a worm vector. cybersecuritysupply-chainmalwarephishingnpm+3 more | ||
Offensive-focused notes on npm supply chain backdoors, Pyarmor stealth stealers, socially engineered RATs, GRU phishing, and weaponized AI safety. infosecmalwaresupply-chainnpmdiscord+3 more | ||
Newsletter on Resecurity's honeypot win, FortiWeb 0-day exploitation, and Chinese Office Assistant supply chain browser plugin attack. cybersecuritydeceptionhoneypotsvulnerabilitiessupply-chain+3 more | ||
| Date | Article | Details |
|---|---|---|
KryptoKat analyzes Coupang's 33.7M-record insider breach, GlassWorm's macOS pivot with Solana C2, Silver Fox tax-themed phishing in India, and Intellexa sanctions reversal. insider-threatglasswormsupply-chainphishingvalleyrat+3 more | ||
React/Next.js exploits compromise 59K servers, browser extensions steal $7M in crypto, and APT groups deploy kernel rootkits for stealthy persistence. supply-chainaptreactnextjsbrowser-extensions+3 more | ||
The threat landscape is ending the year with a bang rather than a whimper. We're seeing critical memory disclosure in one of the world's most popular databases, a ransomware group that's essentially become an industry unto itself, and supply-chain attacks have us jumping at every bump in the night. mongodb mongobleed qilin ransomware developer tools supply-chain attacks+2 more | ||
| Date | Article | Details |
|---|---|---|
Supply-chain attacks target Maven Central with Cobalt Strike, Firefox extensions hide malware in PNG pixels, and APT groups weaponize DNS to hijack software updates. supply-chainmalwaremavenfirefoxbrowser-extensions+3 more | ||
Critical WatchGuard RCE exploited in the wild, 59K Next.js servers compromised, cross-platform APT36 campaigns, and code-signed macOS malware bypassing Gatekeeper. watchguardnextjsapt36macosmalware+3 more | ||
Record 29.7 Tbps DDoS botnet, fresh APT campaigns, mobile and browser malware, and OAuth device code phishing—what defenders must do now. ddosbotnetaptiotzimbra+3 more | ||
| Date | Article | Details |
|---|---|---|
Fortinet and Cisco zero-days, React RCE, Kimwolf botnet, Node.js malware, parked domain abuse, NuGet typosquat, and new Nessus plugins. fortinetciscoreactrcebotnet+2 more | ||
Two offensive tools to watch: SROP-based sleep obfuscation for Linux implants and a local AI auto-exploitation push, with defenses and caveats. sroplinuxevasionobfuscationlocal-ai+1 more | ||
React2Shell exploitation surges, Android trojans and WhatsApp GhostPairing spread, 700Credit breach hits millions, new stealers and APT ops. react2shellandroidwhatsappinfostealerapt15+3 more | ||
| Date | Article | Details |
|---|---|---|
React2Shell RCE slams Next.js as threat actors pivot to BYOVD ransomware, eBPF rootkits, Teams scams, VS Code trojans, and OT bruteforce attacks. reactnextjsrceransomwareebpf+3 more | ||
React2Shell exploited within hours; patch now. Active Gladinet attacks persist. Malware tradecraft and AI-assisted reverse engineering insights. react nextjs rce cve-2025-55182 gladinet+3 more | ||
Nessus plugin refresh expands detections across Linux, QNAP, FreeBSD and PRTG, adding new CVE coverage and TLS configuration checks. nessustenablevulnerability-managementcvelinux+3 more | ||
| Date | Article | Details |
|---|---|---|
Critical React RCE sparks urgent patches as malware campaigns, APT spyware, supply-chain hits, and breaches highlight fragile digital trust. reactrcemalwareaptbreaches+2 more | ||
An in-depth analysis of October-December 2025's major cybersecurity events, including pre-auth RCEs, rootkits on network switches, Windows 10's last free patches, and advanced tradecraft with blockchain C2 and AI phishing. zero-dayrcerootkitexploitblockchain+3 more | ||
4.3M malicious extensions, evolving npm worm and BEC, overlapping APTs, advanced Android banking trojans, and a Rust-based Linux APT toolkit. browser-extensionssupply-chainnpmaptmobile-malware+3 more | ||
| Date | Article | Details |
|---|---|---|
Two weeks of supply chain chaos: npm worm hijacks repos, OAuth integrations abused, APTs use cloud C2, and IoT botnets test massive DDoS. supply-chain npm oauth apt iot+3 more | ||
From PNG-steganography payloads to dev-tool supply chain compromises, attackers scale obfuscation and weaponize trust across platforms. steganographysupply-chainmalwarevscodenpm+3 more | ||
Iranian APTs enabling kinetic strikes, AI botnet via Ray RCE, creative malware via Blender, WhatsApp, homoglyphs, and critical patches. aibotnetrayrcemalware+3 more | ||
| Date | Article | Details |
|---|---|---|
We faced a sprawling mess of supply chain compromises, state-sponsored espionage campaigns, insider threats, mobile malware that bypasses end-to-end encryption, and router hijacking this week. oauth supply chain espionage insider threats mobile malware+1 more | ||
EDR evasion with RONINGLOADER, Windows admin bypass, browser push C2, router AitM updates, Lazarus tweaks, and an ATM heist with a Pi. edr-evasionwindowsprivilege-escalationc2browser-push+3 more | ||
Weekly digest: stego loaders, stealers, APT espionage on aerospace and policy orgs, VDI pivots, and critical RHEL and OT patch updates. steganographymalwarecredential-theftespionageapt41+2 more | ||
| Date | Article | Details |
|---|---|---|
Weekly cybersecurity digest: vendor patches and exploits, major data leaks, evolving malware and autonomous AI-orchestrated espionage, and ransomware fragmentation. patchesbreachesmalwareai-espionageransomware | ||
APT chains hitting Citrix and Cisco with stealthy webshells, new RATs and a Go packer boosting EDR evasion; also destructive ops and proxy C2. zero-dayswebshellsratedr-evasionbulwark+3 more | ||
A roundup of November’s critical patches, active exploits, APT campaigns, supply chain attacks, and evolving phishing threats. cybersecurityvulnerabilitiespatchingzerodaysransomware+3 more | ||
| Date | Article | Details |
|---|---|---|
EvilBit Threat Digest - Cloudy with a Chance of Backups: State Actors, Zero-Days, and the RMM Ruckus Security roundup on cloud backup breaches, critical CVEs, and malware trends, urging patching, credential rotation, MFA, and immutable backups. cloud backups state-actors zero-days rmm+2 more | ||
Explores using Hyper-V as a covert hideout for stealthy C2 and persistence, with real-world campaigns and toolchains. hyper-vedrevasionvirtualizationc2+2 more | ||
Wednesday security digest on urgent patches for WSUS and Android, new APT campaigns, and warnings about dubious AI-driven ransomware claims. wsusandroidcve-2025-59287cve-2025-48593lazarus+1 more | ||
| Date | Article | Details |
|---|---|---|
KEV-heavy week recap: on-prem exploits (SharePoint, VMware Aria, LANSCOPE), Warlock ransomware, and the need for asset visibility. kevon-premsharepointransomwarecve+2 more | ||
A weekly security roundup of VM escapes, DLL hijacks, browser exfiltration tricks, phishing evasion, and hybrid Linux-on-Windows ransomware campaigns. | ||
A tour of evolving cyber threats -from state-sponsored social engineering to zero-days -emphasizing patching, defense in depth, and vigilance. | ||
| Date | Article | Details |
|---|---|---|
Explores how social engineering and human psychology drive modern cyber intrusions, from fake prompts to credential phishing and APT toolsets. | ||
Weekly security roundup of new malware, exploits, supply-chain tricks, and defense notes across Linux, Windows, and cloud. malwareexploitsrcesupply-chaindefense+3 more | ||
A roundup of firewall flaws and edge-security woes: WatchGuard RCE, Zyxel bypasses, eBPF rootkits, and evolving cloud threats. firewallwatchguardzyxelcve-2025-9242cve-2025-8078+2 more | ||
| Date | Article | Details |
|---|---|---|
Security roundup detailing F5 compromise, Patch Tuesday Windows EoPs, GoAnywhere MFT exploit, KEV updates, and practical mitigations f5patch-tuesdaykevmftgoanywhere-mft+2 more | ||
Time-critical guidance to inventory, isolate, patch, and rotate credentials for F5 devices; apply ED 26-01; KEV flags Windows EoPs. f5cisaed-26-01kevwindows+1 more | ||
Overview of October 2025 Patch Tuesday: four high-risk flaws, patch priorities, and guidance as Windows 10 reaches end of support. patch-tuesdaywsusrasmanoffice-previewagere-driver+1 more | ||
| Date | Article | Details |
|---|---|---|
A weekly security briefing on active exploits (Oracle EBS CVE-2025-61882), botnets, phishing, and urgent patching and defense guidance. oracleebscve-2025-61882rondodoxghostrat+3 more | ||
Threat briefing on edge campaigns: RondoDox, phpMyAdmin poisoning, Gladinet 0-day, SonicWall backups breach, with quick defensive actions. edgerondodoxphpmyadmingladinetsonicwall+1 more | ||
Oracle EBS zero-day in the wild, Red Hat GitLab breach spills 570 GB of secrets, stealthy BRICKSTORM backdoors lurk in appliances — patch, hunt, log | ||
| Date | Article | Details |
|---|---|---|
Attackers exploit critical vulnerabilities across enterprise software, turning middleware and perimeters into breach playgrounds | ||
The OpenAI and Hugging Face agent swarm, a record 974-CVE Patch Tuesday, and an actively exploited CVSS 10.0 in Cisco Secure FMC.
A cross-cutting security digest on geopolitics shaping outages, new APT chains, AI prompt risks, cryptomining, and pragmatic patching guidance.