Chaos-linked msaRAT drives headless Chrome or Edge over CDP, relaying encrypted C2 through Twilio TURN while its own process stays on loopback.
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.
The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias “Kontraktnik,” promoting it as an all-in-one remote access trojan.
According to Varonis, the operator panel lists 329 features across ten categories, including a credential-stealing feature that claims to target more than 300 applications.
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.
At least 29 organizations were compromised between July 21–22 during the malicious operation, which researchers call FakeAgent.
The attackers used a malicious Claude Artifact hosted on Claude’s legitimate domain, a tactic that has been used at the beginning of the year to push macOS malware via ClickFix lures.
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.
The high-severity flaw, tracked as CVE-2026–8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as 442 security flaws in Linux have been publicized over the past three days.
“The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox initialization,” Saeed Abbasi, head of Threat Research Unit (TRU) and director of product at Qualys, said.
Enterprise AI will continue expanding because the business benefits are clear. The challenge is ensuring that productivity gains do not come at the expense of security.
The most effective approach is to incorporate AI into existing identity, data protection and incident response strategies rather than treating it as a separate security domain. Organizations should evaluate AI security controls based on how well they integrate with existing governance and security operations while providing visibility into AI usage, permissions and policy violations.
For managed service providers (MSPs) and enterprise security teams, there is an opportunity to extend cyber resilience strategies to include AI governance.
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
During the operation, authorities seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable.
The action was led by Frankfurt’s Prosecutor General Office (ZIT), Germany’s Federal police (BKA), which worked in collaboration with U.S. law enforcement agencies.
A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
Over 800 repositories pretended to be AI skills or MCP servers and appeared more than 600 times in public AI registries and catalogs. This increased the likelihood of being discovered by AI agents and developers, a technique that researchers call “agentbaiting.”
The campaign is considered a continuation of an older operation that used Lumma Stealer and was attributed to a threat actor tracked as “Water Kurita” by researchers at cybersecurity company Trend Micro.