BleepingComputer
Indicators
Reports whose articles were checked and found to contain indicators. Counts are measured, not guessed: open a report, read it, take the addresses. Verify every one before it goes anywhere near a block list — a count is evidence a report is worth your time, not that an address is hostile.
Microsoft Security
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
BleepingComputer
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA
#StopRansomware: Gunra Ransomware
BleepingComputer
Critical Progress LoadMaster flaw now actively exploited in attacks
The Hacker News
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
BleepingComputer
Metabase SQLi zero-day exploited in customer data-theft attacks
Microsoft Security
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
Microsoft Security
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
Fortinet
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
Malware Traffic Analysis
2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT
Securelist
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Unit 42
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Securelist
Toy Ghouls’ new toy: the GenieLocker ransomware
Zscaler ThreatLabz
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Elastic Security Labs
New North Korean campaign uses fake coding interviews to steal developer credentials
Fortinet
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
Cisco Talos
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Elastic Security Labs
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
Zscaler ThreatLabz
ClaudeFix: Shared Claude Chats Meet ClickFix
Huntress
Threat Actors Achieve Persistence After SQL Injection
Elastic Security Labs
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
Unit 42
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
The DFIR Report
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Huntress
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Zscaler ThreatLabz
SmartApeSG Launches Okendo Reviews Supply Chain Attack
Zscaler ThreatLabz
ClickFix Campaign Generated Via AI Delivers SmartRAT
Huntress
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
Zscaler ThreatLabz
Shai-Hulud Campaign Evolution: Miasma, Hades, and AI Scanner Evasion
Huntress
Inside Kali365, a Device Code Phishing Ecosystem | Huntress
Zscaler ThreatLabz
Technical Analysis of MLTBackdoor
Fortinet
Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
Huntress
The Gentleman Ransomware | Defense Evasion TTPs Uncovered | Huntress
Huntress
Threat Actor Defense Evasion: How Attackers Disable AV & EDR
The DFIR Report
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
The DFIR Report
Apache ActiveMQ Exploit Leads to LockBit Ransomware
The DFIR Report
Cat’s Got Your Files: Lynx Ransomware