HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm Source: The Hacker News Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted arc Read original

ESET tracks rise in malicious AI skills and adaptable malware

ESET tracks rise in malicious AI skills and adaptable malware Source: BleepingComputer Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET’s new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security soft Read original

ESET tracks rise in malicious AI skills and adaptable malware

ESET tracks rise in malicious AI skills and adaptable malware Source: BleepingComputer Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET’s new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security soft Read original

ESET tracks rise in malicious AI skills and adaptable malware

ESET tracks rise in malicious AI skills and adaptable malware Source: BleepingComputer Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET’s new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security soft Read original

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests Source: BleepingComputer One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. […] Read original

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests Source: BleepingComputer One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. […] Read original

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests Source: BleepingComputer One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. […] Read original

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests Source: BleepingComputer One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. […] Read original

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic Source: BleepingComputer The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. […] Read original

July 23, 2026 Updated: October 8, 2026 1 min

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Source: The Hacker News Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation o Read original