Skip to content

Derp | Security Research

Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.

Security News

  1. Exposed Robobox Infrastructure Links AI-Assisted Malware Toolkit to Coruna iOS C2opens in a new tab

    Netaskari Substack

  2. CrySyS Lab Introduces EMBeD Benchmark for IoT Malware Detectionopens in a new tab

    malware.news

  3. Leaked AWS IAM Key Used to Steal and Resell Paid Bedrock AI Accessopens in a new tab

    Cyber Security

  4. DPRK-Linked Contagious Interview Uses Trojanized macOS Installers to Deploy OtterCookieopens in a new tab

    Lazarusholic Bluesky

  5. Signed Shift Browser Adware Fingerprints Hosts Before Installing Browser Payloadopens in a new tab

    Heimdalsecurity Com Threat Center

  6. MECCHA CHAMELEON Steam Workshop Maps Enabled Two-Click RCEopens in a new tab

    Aikido Dev

  7. Wyden Urges NSA Warning That Single-Hop VPNs Enable Traffic Correlationopens in a new tab

    malware.news

  8. Goja TypedArray Memory Corruption Enables RCE in Zendesk and Nucleiopens in a new tab

    Slcyber

  9. Path Traversal and Upload Path Tampering in Telerik UI for ASP.NET AJAXopens in a new tab

    malware.news

  10. Russian National Extradited Over Freelancer Platform Malware Campaignopens in a new tab

    Infosecurity Magazine

  11. TukTuk Framework Enables Credential Theft and EDR Evasion for Gentlemen Ransomwareopens in a new tab

    Cyber Security

  12. Gambling Goblin Hijacks Brazilian Websites for Gambling SEO Fraudopens in a new tab

    Infosecurity Magazine

  13. Public Exploit Targets Cleo Harmony JWT Authentication Bypassopens in a new tab

    Cyber Security

  14. Knight Office AiTM Kit Steals Microsoft 365 Sessions and Establishes Entra Persistenceopens in a new tab

    IT Security Guru

  15. Kimsuky Uses Seafood Purchase Lure to Deploy Backblaze B2-Backed Malwareopens in a new tab

    Lazarusholic Bluesky

  16. AI-Assisted Ransomware Attack Compromised Enterprise via Public APIopens in a new tab

    Unit 42

  17. ExfilSquad Extorts UK Institutions With Stolen Cloud and CRM Dataopens in a new tab

    malware.news

  18. International Operation Sinkholes Sality Botnet and Seizes Payload Domainsopens in a new tab

    Help Net Security

  19. SafePay Ransomware Abuses OneDrive for Stealthy Data Exfiltrationopens in a new tab

    malware.news

  20. Microsoft to Enable Memory Integrity by Default on Eligible Windows 11 PCsopens in a new tab

    Windowslatest

  21. Actively Exploited SonicWall SMA1000 Flaws Enable SSRF and Command Executionopens in a new tab

    BleepingComputer

  22. Email Parsing Flaws Let Attackers Hijack AI Customer-Service Agentsopens in a new tab

    Intigriti

  23. Counterfeit Software Installers Deliver Silver Fox-Like Malware Campaignopens in a new tab

    malware.news

  24. Nexus Dark-Web Service Sells 153 Million Driver’s License Scansopens in a new tab

    malware.news

  25. Ransomware Groups Recruit Insiders for Corporate Network Accessopens in a new tab

    Dark Reading

  26. Phishing Campaign Abuses Faronics Deploy to Install ScreenConnectopens in a new tab

    BleepingComputer

  27. Leaked Bauman Records Expose Russian Military Cyber Recruitment Pipelineopens in a new tab

    Gbhackers

  28. Critical JFrog Artifactory Authentication Bypass Exploited for Admin Tokensopens in a new tab

    Decipher Sc

  29. Malicious npm Dependency Chain Delivers Cross-Platform Remote-Access Trojanopens in a new tab

    Lazarusholic Bluesky

  30. Chameleon SEO Poisoning Drives Banking Phishing Pages Above Search Resultsopens in a new tab

    Knowbe4

  31. ClickFix Campaign Abuses ChatGPT Links to Deploy NetSupport Remote-Access Malwareopens in a new tab

    Cyber Security

  32. Active Exploitation of Sangoma Switchvox SQL Injection Enables RCEopens in a new tab

    Reddit Netsec

  33. Attackers Exploit Critical Langflow RCE to Harvest Cloud and SSH Credentialsopens in a new tab

    SecurityWeek

  34. Indian Data Broker Sells Unauthorized KYC Records via Telegram and APIopens in a new tab

    malware.news

  35. Chrome Web Store Permanently Removes Manifest V2 Extensionsopens in a new tab

    Thecybersecguru

  36. BREEZE COMET Targets Brazilian Financial Networks for Fraudulent Transfersopens in a new tab

    Mandiant

  37. Trojanized Exodus Wallet Installer Deploys Modular Memory-Resident RATopens in a new tab

    Huntress

  38. MCPJacking Exposes 155 Stale MCP Registry Entries to Domain Takeoversopens in a new tab

    Cyberveille

  39. OEMPocalypse Exploit Chains Achieve Kernel Compromise on Major Android OEMsopens in a new tab

    malware.news

  40. Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attemptopens in a new tab

    The Record Media

  41. Rogue Free LLM Endpoint Captures Coding-Agent Context and Tool Accessopens in a new tab

    malware.news

  42. White House Launches Texas Water-System Cybersecurity Pilotopens in a new tab

    Cyberscoop

  43. Manic Android Trojan Relays Stolen Banking Data Through Nearby Devicesopens in a new tab

    Kaspersky

  44. Dependency Cooldowns Limit Exposure to Malicious Package Releasesopens in a new tab

    The New Stack

  45. Trojanized Packagist Themes Use FUNNULL-Hosted iPhone Spyware Chainopens in a new tab

    Socket

  46. Orova Claims Theft of 150,000 Cardiology Associates Patient Recordsopens in a new tab

    malware.news

  47. Global Ransomware Activity Reaches 2026 High With 894 July Victimsopens in a new tab

    Zdnet

  48. OpenClaw 2.0 Adds Credential, Plugin and AI-Agent Security Controlsopens in a new tab

    Cyber Security

  49. ValleyRAT Backdoor Delivered Through Trojanized QN Wallpaper Adwareopens in a new tab

    malware.news

  50. Spring Ring Uses Microsoft Teams Vishing to Pursue Domain Compromiseopens in a new tab

    Unit 42

  51. Nigerian Sextortion Suspects Extradited to Face Charges Linked to Teen Deathsopens in a new tab

    BleepingComputer

  52. China-Linked Fire Ant Abuses Trusted Infrastructure for Espionageopens in a new tab

    The Hacker News

  53. Fraudulent School Websites Target Students, Parents and Educatorsopens in a new tab

    malware.news

  54. Automated Bots Consume Nearly All git.kernel.org Trafficopens in a new tab

    Opennet

  55. TerminalFix ClickFix Campaign Establishes Reverse-Tunnel Access Through Compromised Hostsopens in a new tab

    malware.news

  56. McKesson Investigates Data Theft Claim After Third-Party Application Breachopens in a new tab

    malware.news

  57. OpenAPI React Query Codegen npm Releases Deliver Credential-Stealing Supply-Chain Malwareopens in a new tab

    StepSecurity

  58. Magecart Skimmers Abuse Stripe APIs and Ethereum Contracts for Payload Deliveryopens in a new tab

    Confiant

  59. KubeCap Identifies Excess Linux Capabilities in Kubernetes Workloadsopens in a new tab

    Linuxsecurity

  60. X Dismantles Suspected China-Linked Bot Farm Targeting AI Data-Center Debateopens in a new tab

    Foxbusiness

  61. Zoom macOS ZoomOpener Flaw Enabled Website-Triggered RCEopens in a new tab

    Slcyber

  62. Unauthenticated File Disclosure in Sitecore Can Lead to Remote Code Executionopens in a new tab

    Slcyber

  63. Great Firewall DNS Poisoning Enables Domain Hijacking and XSS Risksopens in a new tab

    Slcyber

  64. Citrix Bleed CVE-2023-4966 Leaks NetScaler Session Tokensopens in a new tab

    Slcyber

  65. Craft CMS RCE Exploits PHP argv Handling and FTP Template Loadingopens in a new tab

    Slcyber

  66. Cloudflare Pages Flaws Exposed Git Credentials and Enabled Container-to-Host Accessopens in a new tab

    Slcyber

  67. Citrix ADC CVE-2023-3519 Analysis Identifies Pre-Auth Memory-Corruption Pathsopens in a new tab

    Slcyber

  68. Metabase Setup Token Flaw Enables Unauthenticated Remote Code Executionopens in a new tab

    Slcyber

  69. Unauthenticated RCE in Citrix ShareFile StorageZones Controlleropens in a new tab

    Slcyber

  70. Flarum Avatar Flaw Enables Local File Disclosure and Blind SSRFopens in a new tab

    Slcyber

  71. CISA Flags Actively Exploited ownCloud, Linux Kernel and JFrog Artifactory Flawsopens in a new tab

    Security Affairs

  72. Root Backdoors Found in Globally Rebranded ZBT Router Firmwareopens in a new tab

    Heise

  73. Critical cPanel Flaw Lets Hosting Users Escalate to Root Server Controlopens in a new tab

    The Hacker News

  74. Critical Pre-Authentication RCE Flaws Expose WatchGuard Fireware VPNsopens in a new tab

    Csirt Italia

Trackers

Latest Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.