Researchers Link DigiCert Security Incident To GoldenEyeDog Subgroup
Security researchers have linked the April 2026 DigiCert security incident to a GoldenEyeDog subgroup that allegedly stole code signing certificates and used them to sign malware.
Security researchers have linked the April 2026 DigiCert security incident to a GoldenEyeDog subgroup that allegedly stole code signing certificates and used them to sign malware.
Kaspersky has uncovered the GoSerpent malware campaign targeting government and diplomatic organizations in Southeast Asia with advanced espionage, credential theft, and data exfiltration capabilities.
Microsoft has warned of active ACR Stealer campaigns using ClickFix lures to steal browser credentials, authentication tokens, Microsoft 365 files, and sensitive enterprise data through fileless and disk based attack chains.
Researchers warn that the latest RedHook Android malware abuses Wireless ADB and Accessibility permissions to gain deep device access and steal banking credentials without requiring root access.
Researchers have identified CrashStealer, a new macOS information stealing malware that uses an Apple notarized dropper to bypass Gatekeeper while targeting browser data, cryptocurrency wallets, password managers, and keychain credentials.
National CERT Pakistan has issued an advisory warning organizations to immediately patch critical FortiSandbox vulnerabilities that are being actively targeted through internet facing systems.
Researchers have linked the Silver Fox cybercrime group to a new Rust based remote access trojan called MODBEACON that uses gRPC streaming and encrypted command and control channels to target organizations across Asia.
Researchers have identified a new modular Cavern command and control framework used by an Iran linked hacking group to target government and IT organizations through supply chain attacks, advanced malware, and post exploitation techniques.
A threat actor known as Armored Likho has been linked to cyber espionage campaigns targeting government and power sectors using BusySnake Stealer, RAT tools, and phishing-based attack chains.
Threat actors are actively exploiting SimpleHelp vulnerability CVE 2026 48558 to deploy TaskWeaver and Djinn Stealer, targeting cloud credentials, AI tools, cryptocurrency wallets, and enterprise infrastructure.