Derp | Security Research
Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.
Security News
RovoBlast Prompt Injection Flaw Let Atlassian Rovo Exfiltrate Sensitive Dataopens in a new tab
Cysecurity
Kata Containers Flaw Enables Host Root Code Execution via Config Path Annotationopens in a new tab
Cvefeed High Severity
Ransomware Attack Disrupts City of Coweta Systems While Emergency Services Stay Onlineopens in a new tab
malware.news
Metabase SQLi Zero-Day Exposed Customer Data at Framework and Tallyopens in a new tab
BleepingComputer
Suspicious macOS Coding-Agent Activity Used Tunnels and LaunchAgent Persistenceopens in a new tab
Elastic Security Labs
Levi Strauss Breach Exfiltrated Corporate Data via Social Engineeringopens in a new tab
BleepingComputer
Patchwork used fake PDFs and trojanized chat apps to spy on Windows and Android targetsopens in a new tab
Cyber Security
22 Vulnerabilities in TeamDavid Expose Mailboxes, Files, and Server Secretsopens in a new tab
Cvefeed High Severity
Deepfake Scammers Impersonate OnlyFans Creators to Steal Money From Fansopens in a new tab
Security Affairs
Microsoft 365 Phishing Campaign Hijacks Identities for Stealthy BEC and Mail Accessopens in a new tab
malware.news
Nx Self-Hosted Remote Cache Flaw Enables Arbitrary File Write and RCEopens in a new tab
Cvefeed High Severity
UNC6671 Expands Vishing Extortion Under Redact, Pink, Helix, and Falcon Brandsopens in a new tab
Techcrunch Com Security
Orova ransomware campaign expands across SMBs and exposes U.S. healthcare dataopens in a new tab
malware.news
Apple Patches macOS Screen Sharing Authentication Bypass and CUPS Root Write Flawopens in a new tab
Tidbits
Pre-authentication Root RCE Flaws Expose Xeams Mail Serversopens in a new tab
Fulldisclosure Mailing List
Pre-authentication SYSTEM RCE Disclosed in Vicon Valerus ViconNet Gatewayopens in a new tab
Fulldisclosure Mailing List
Pre-authentication RCE in Unity Version Control On-Prem via Plastic SCM defaultsopens in a new tab
Fulldisclosure Mailing List
Pre-authentication Root RCE Chain and Default Admin Password Exposed in CatDV Serveropens in a new tab
Fulldisclosure Mailing List
Linux Safe RET Flaw on AMD Zen CPUs Enables Interrupt Injection Data Leaksopens in a new tab
BleepingComputer
Vanta Stealer Harvests Browser Credentials, Crypto Wallets, and Gaming Accountsopens in a new tab
Cyber Security
Ransomware Campaign Targeted Managers to Gain Business Access and Boost Extortionopens in a new tab
malware.news
Larva-26005 Links Xctdoor Campaign to Earlier CRAT Intrusions in South Koreaopens in a new tab
Lazarusholic Bluesky
CISA Flags Actively Exploited JetBrains TeamCity RCEopens in a new tab
Cyber Security
Cisco IMC RCE and Widespread BMC Flaws Expose Server Management Controllersopens in a new tab
Arstechnica Security
Canadian Hacker Pleads Guilty in Snowflake-Linked Breach and Extortion Spreeopens in a new tab
malware.news
Nuxt Server Island Template Injection Flaw Enables Server-Side RCEopens in a new tab
Cvefeed High Severity
Shai-Hulud CHAINDROP Worm Backdoors 400+ npm Packages via keyv Compromiseopens in a new tab
Elastic Security Labs
Flooding Dropper Campaign Seeds 850 Malicious npm Packagesopens in a new tab
malware.news
Bixby exploit chain enabled remote system compromise on Samsung phonesopens in a new tab
SecurityWeek
macOS ClickFix Campaign Hid AMOS and MacSync Behind Fingerprinting Gatesopens in a new tab
The Hacker News
Poison Claude Resold Anthropic Access Through Fraudulent Cloud Accountsopens in a new tab
Cyber Security
Apache Answer Flaw Enables Account Takeover via OAuth Email-Binding Flowopens in a new tab
Oss Security Mailing List
PhaaS Kits Bypass MFA to Hijack Microsoft 365 Accounts at U.S. Organizationsopens in a new tab
Cyber Security
Root-Level ENDLESSDOORS Implant Found in Zbtlink Routersopens in a new tab
Decipher Sc
Windows Hello Key Abuse Enables Entra ID Token Theft and Persistenceopens in a new tab
Dirkjanm
Frontier AI agents crossed test boundaries and triggered UK and US scrutinyopens in a new tab
Decipher Sc
CISA Adds Exploited Langflow, Tomcat, and N-central Flaws to KEVopens in a new tab
SecurityWeek
Privilege Escalation in Red Hat ClusterCurator Grants Full Kubernetes Cluster Controlopens in a new tab
Cvefeed High Severity
Qilin Ransomware Drives UK Victim Surge and Hits Intertrust Australiaopens in a new tab
malware.news
One-Click RCE in VS Code, Cursor, and Google Antigravityopens in a new tab
Cyber Security
Odysseus Flaw Let Non-Admins Hijack Embedding Endpoint and Exfiltrate Dataopens in a new tab
Cvefeed High Severity
Greatness PhaaS Adds Device-Code Phishing to Hijack Microsoft 365 Accountsopens in a new tab
BleepingComputer
Google::Auth for Perl Flaw Enables SSRF and Credential Exfiltration via Credentials JSONopens in a new tab
Oss Security Mailing List
Microsoft Defender Automatically Isolated a QNET Device to Stop Ransomwareopens in a new tab
malware.news
Smoke#Screen Campaign Abuses ScreenConnect for Stealthy Cross-Platform Accessopens in a new tab
Dark Reading
OpenAI Moves Codex Into Persistent Cloud Workspaces Through Ona Acquisitionopens in a new tab
The New Stack
Email AI Assistants Abused to Hijack CEO Accounts and Redirect Wire Transfersopens in a new tab
Cyber Security
Malicious Keyv npm Releases Used Trusted Publishing to Steal Developer Secretsopens in a new tab
SC World
OWASP Launches Subtractive Security Top 10 to Eliminate Attack Pathsopens in a new tab
Cyber Security
Swiss Federal IT Office Breach Compromised 200 SharePoint Accountsopens in a new tab
malware.news
Direct-to-IP Malware Traffic Bypasses DNS Defenses at Scaleopens in a new tab
Unit 42
Deepfakes and Agentic AI Raise Fraud and Control Risks in Digital Paymentsopens in a new tab
Bluescreen Kz
Phishers Abuse Cloudflare, Vercel, GitHub Pages, and IPFS to Host AiTM Campaignsopens in a new tab
malware.news
Google Withdraws Google Earth AI Imagery Tool After Deepfake Abuse Concernsopens in a new tab
malware.news
ChainDrop npm Worm Compromises Packages via Preinstall Credential Harvesteropens in a new tab
Cryptika
Fake IRS Letters Lure Crypto Holders to Phishing Compliance Portalopens in a new tab
Bitdefender
Microsoft Excel Use-After-Free Flaw Enables Remote Code Executionopens in a new tab
ThreatAft
New York Expands Cybersecurity Mandates and Grants for Water Utilitiesopens in a new tab
SecurityWeek
Microsoft Adds Teams Reporting Tools to Counter AI Deepfake and Meeting Fraudopens in a new tab
Windowslatest
Trusted Coding Projects Can Trigger Code Execution Before User Interactionopens in a new tab
Reddit Netsec
Fake Xeno Roblox Executor Spreads Java Stealer and RAT via Discordopens in a new tab
BleepingComputer
Public RefluXFS PoC Targets Linux Kernel XFS Reflink Privilege Escalationopens in a new tab
Oss Security Mailing List
Qilin ransomware claims string of victims across U.S. and Europeopens in a new tab
malware.news
Critical OpenEMR RCE Lets Database Payloads Trigger PHP Code Executionopens in a new tab
Cvefeed High Severity
Critical Krayin CRM Flaw Lets Unauthenticated Attackers Take Over Admin Accountsopens in a new tab
Cvefeed High Severity
River Bank Says Stolen Data Was Deleted After June Ransomware Attackopens in a new tab
Security Affairs
Brazilian Schools Hit by Ransomware, Valid Account Abuse, and Insider Keyloggingopens in a new tab
Securelist
CTI-Transmute PDF Rendering Flaw Enabled SSRF and Local File Disclosureopens in a new tab
Cvefeed High Severity
Novel Malware Attacks Hijack Google-Synced Passkeys on Chromeopens in a new tab
Unit 42
Larva-24009 Phishing Campaign Delivers Malware to South Korean and Global Targetsopens in a new tab
malware.news
Elastic Defend Expands BYOVD Detection to 800+ Vulnerable Windows Driversopens in a new tab
Help Net Security
AI-Enabled Threat Actors Accelerate Exploitation and Target AI Infrastructureopens in a new tab
Cyberscoop
Trackers
Distribution
- 5,841
- unique hosts seen in 7 days
- 137
- families in the feed
Malware C2
- 4,279
- unique C2 hosts seen in 7 days
- 202
- families in the feed
PhaaS
- 15,688
- domains under tracking
- +563
- added in the last 7 days
ClickFix
- 10,210
- domains under tracking
- +2,179
- added in the last 7 days
Ransomware
- 329
- victims named in 7 days
- 70
- groups active in 30 days
npm
- 500
- releases flagged in 14 days
- 191
- confirmed malicious
Latest Research
11 min read
1,509 WordPress sites feed an active SocGholish chain
One integrated WordPress-to-GhoLoader operation mapped to Proofpoint's TA2726 and TA569/SocGholish labels, followed by ClickFix on shared hosts.
15 min read
From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io
Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.
23 min read
SilverFox-style loader chain: Panasonic shells, Alibaba OSS carriers, and a Sauron backdoor
Technical analysis of a SilverFox-style loader chain hiding behind Panasonic PC Notification metadata, using Alibaba OSS carriers, signed side-load hosts, RPC Task Scheduler staging, and a Sauron backdoor.
13 min read
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
Deep-dive analysis of a trojanized Roblox executor that functions as a highly convincing lure with live DeepSeek script generation, while silently staging a Python 3.12 variant of Glove Stealer that bypasses Google Chrome's App-Bound Encryption.