Derp | Security Research
Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.
Security News
OpenAPI React Query Codegen npm Releases Deliver Credential-Stealing Supply-Chain Malwareopens in a new tab
StepSecurity
Magecart Skimmers Abuse Stripe APIs and Ethereum Contracts for Payload Deliveryopens in a new tab
Confiant
X Dismantles Suspected China-Linked Bot Farm Targeting AI Data-Center Debateopens in a new tab
Foxbusiness
CISA Flags Actively Exploited ownCloud, Linux Kernel and JFrog Artifactory Flawsopens in a new tab
Security Affairs
Root Backdoors Found in Globally Rebranded ZBT Router Firmwareopens in a new tab
Heise
Critical cPanel Flaw Lets Hosting Users Escalate to Root Server Controlopens in a new tab
The Hacker News
Critical Pre-Authentication RCE Flaws Expose WatchGuard Fireware VPNsopens in a new tab
Csirt Italia
CISA Finds Known Internet-Exposed Flaws Drive Most Damaging Compromisesopens in a new tab
Security Online Info
Log4Shell RCE in Apache Log4j Exposes Java Applicationsopens in a new tab
Tenable Nessus Plugins
Agentic AI Enables Rapid Enterprise Attacks and Expands Threat Actor Capabilityopens in a new tab
Cyberscoop
Dark-Web Marketplaces Sell Corporate Executive SSNs for $0.25opens in a new tab
Cyber Security
PaperCut NG/MF Zero-Day Exploited on Internet-Exposed Serversopens in a new tab
BleepingComputer
Manchester Airports Group Customer Data Stolen in Cybersecurity Incidentopens in a new tab
BleepingComputer
AI Coding Agents Installed Unclaimed Packages Referenced in llms.txt Filesopens in a new tab
Arstechnica Security
Criminal Forums Commercialize AI Tools for Ransomware and Spear-Phishingopens in a new tab
Knowbe4
CISA Flags Six Actively Exploited NetScaler, SQL Server, Linux, and Red Hat Flawsopens in a new tab
Infosecurity Magazine
Misconfigured AD CS Templates Enable Domain Privilege Escalationopens in a new tab
Guidepoint Security
Polymorphic JavaScript Phishing Page Evades Detection and Can Hang Browsersopens in a new tab
malware.news
ICS Malware Blocking Falls to Four-Year Low as Email Threats Riseopens in a new tab
Securelist
Critical WatchGuard Windows Agent Flaws Enable Unauthenticated SYSTEM-Level RCEopens in a new tab
Cyber Security
Coordinated Intrusion Disrupts Remote Monitoring at Minnesota Water Utilitiesopens in a new tab
Optiv
NSA Recruits Former TAO Operators to Rebuild Elite Hacking Unitopens in a new tab
malware.news
FBI Disrupts QTFY Proxy Network Used to Breach U.S. Federal Agenciesopens in a new tab
Cyberscoop
Attackers Target Exposed AI Control Planes for Credentials and Cryptominingopens in a new tab
malware.news
Critical Unauthenticated RCE Chain in SENAITE.CORE JSON APIopens in a new tab
Cvefeed High Severity
Tortoiseshell Deploys C++ Backdoor and Reverse SSH Tunneling Infrastructureopens in a new tab
The Record Media
LLM-Integrated Malware and Agentic AI Ransomware Emergeopens in a new tab
Zdnet Zero Day
Log4j2 MarshalledObject Deserialization Bypass Enables Conditional RCEopens in a new tab
Thecybersecguru
Suspected Chinese-Speaking Operator Breaches Philippine Nuclear and Naval Organizationsopens in a new tab
Reddit Netsec
China-Linked Espionage Exploits Edge Devices to Target High-Value Organizationsopens in a new tab
Tenable
Ivanti EPMM Zero-Days Exploited Amid Broad Edge Infrastructure Targetingopens in a new tab
Sentinelone
Fake Claude Desktop Ads Deliver SectopRAT and Disable Microsoft Defenderopens in a new tab
Cyber Security
Dark Caracal Targets Venezuelan Communications Organization With Ethereum-Based C2opens in a new tab
malware.news
SonicWall NetExtender Linux Flaws Enable Root-Level Arbitrary File Writesopens in a new tab
Cyber Security
OpenAI Bans Russian Accounts Operating Fake Think Tank Influence Campaignopens in a new tab
Toms Hardware
MuddyWater Hides Dindoor Backdoor Execution in Signed Deno Runtimeopens in a new tab
Cyber Security
CrashFix Campaign Uses Fake Chrome Repair to Deploy ModeloRATopens in a new tab
malware.news
OpenStack Keystone Flaws Let Delegated Tokens Escape Project Scopeopens in a new tab
Oss Security Mailing List
Critical Unauthenticated File Write in DB-GPT Skill Upload Enables RCEopens in a new tab
Cvefeed High Severity
NVIDIA NemoClaw Flaw Lets Malicious Websites Persistently Poison Local AI Modelsopens in a new tab
Cvefeed High Severity
CISA Red Team Exposes Government SOC Failure and Water-Sector Resilienceopens in a new tab
Cyberscoop
OpenRGB Server Flaws Enable Arbitrary File Overwrite and Remote Root Compromiseopens in a new tab
Oss Security Mailing List
Seoul National University Hospital Faces Scrutiny Over Cybersecurity Reporting After 830,000-Record Breachopens in a new tab
malware.news
AI Agent Swarm Breached Asian Government Systems and Stole Personnel Recordsopens in a new tab
Cyber Security
INTERPOL Operation Jackal IV Disrupts West African Cybercrime Networksopens in a new tab
Help Net Security
RecruitTrap Mobile Phishing Campaign Targets Enterprise Credentialsopens in a new tab
Infosecurity Magazine
Malicious npm Packages Used to Host Fake Cloudflare CAPTCHA Phishing Pagesopens in a new tab
The Hacker News
Actively Exploited Oracle WebLogic and HTTP Server Flaw Enables Full Compromiseopens in a new tab
Register Security
Palo Alto Finds Most AI-Enabled Malware Remains Experimental or AI-Brandedopens in a new tab
Unit 42
EvilTokens Device Code Phishing Uses Notion Lures to Steal Microsoft 365 Tokensopens in a new tab
Cyber Security
WeedHack Infostealer Persists Through Fake Minecraft Sites and SEO Poisoningopens in a new tab
Security Affairs
Chrome 152 Adds Connection Allowlists and Enhanced Safe Browsing Warningsopens in a new tab
Chrome Developer
sg3_utils `sg_inq --export` Flaw Enables Root Command Execution via udev Injectionopens in a new tab
Redhat Access
libXfont2 Font Server Flaws Enable X Server Privilege Escalationopens in a new tab
Redhat Access
Void Arachne Pushes Winos 4.0 via Trojanized AI, VPN, and Telegram Installersopens in a new tab
Trendai Security
PolinRider Campaign Hijacked GitHub Maintainer Accounts to Push Malware to npmopens in a new tab
Opensourcemalware
Treasury Sanctions Iran-Linked Hackers and Crypto Addresses in Economic Outcastopens in a new tab
Trm Labs
US Sanctions Iranian Hackers Linked to Critical Infrastructure Intrusionsopens in a new tab
The Record Media
miniOrange WordPress SSO Flaws Exploited for Administrator Account Takeoveropens in a new tab
SC World
PE Metadata and Icons Can Be Faked to Masquerade Unsigned Windows Malwareopens in a new tab
malware.news
Ascent Nursing Facilities Disclose Vendor-Linked PHI Breach Affecting Residentsopens in a new tab
malware.news
AI Agent Flaws Expose RCE, Sandbox Escape, and Supply-Chain Attack Pathsopens in a new tab
The New Stack
Microsoft Teams Adds Policy to Automatically Block External Meeting Botsopens in a new tab
Cyber Security
Fake Microsoft SysScan Sites Push Victims to Remove Antivirusopens in a new tab
malware.news
Malicious Firefox Add-ons Stole Crypto Wallet Seed Phrases and Browser Credentialsopens in a new tab
Bitdefender
Kimsuky Used AI-Built Chrome Extension and Remote Tools to Steal Gmail Dataopens in a new tab
Cyber Security
WebKitGTK Use-After-Free Flaw Exposes RHEL Systems to Possible Remote Code Executionopens in a new tab
Bugzilla Redhat
AliExpress Used Silent Web Audio Fingerprinting to Track Shoppersopens in a new tab
Register Security
PavinLoader Linked to ClickFix, Fake Downloads, and RenPy Malware Campaignsopens in a new tab
malware.news
Hugo SSRF Flaw Lets `resources.GetRemote` Reach Internal and Metadata Endpointsopens in a new tab
Cvefeed High Severity
AnonyMousKIT Used AI Phishing to Steal Apple IDs and Unlock Stolen Devicesopens in a new tab
SOCRadar
Fake GTA VI ISO Torrent Used to Deliver Malware and Disable Defensesopens in a new tab
Heise
WebKitGTK Permissions Flaw Lets Malicious Websites Leak Sensitive Dataopens in a new tab
Redhat
Trackers
Distribution
- 19,698
- unique hosts seen in 7 days
- 191
- families in the feed
Malware C2
- 5,511
- unique C2 hosts seen in 7 days
- 269
- families in the feed
PhaaS
- 14,441
- domains under tracking
- +1,729
- added in the last 7 days
ClickFix
- 24,071
- domains under tracking
- +4,648
- added in the last 7 days
Ransomware
- 252
- victims named in 7 days
- 82
- groups active in 30 days
npm
- 325
- releases flagged in 7 days
- 141
- confirmed malicious
Latest Research
8 min read
ClickFix via Cloudflare Zaraz and the BW Panel
A malicious Cloudflare Zaraz action on edgeupstudio[.]com loaded an ErrTraffic BW Panel bootstrap that looked up its panel address in a Polygon contract.
11 min read
1,509 WordPress sites feed an active SocGholish chain
One integrated WordPress-to-GhoLoader operation mapped to Proofpoint's TA2726 and TA569/SocGholish labels, followed by ClickFix on shared hosts.
15 min read
From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io
Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.
23 min read
SilverFox-style loader chain: Panasonic shells, Alibaba OSS carriers, and a Sauron backdoor
Technical analysis of a SilverFox-style loader chain hiding behind Panasonic PC Notification metadata, using Alibaba OSS carriers, signed side-load hosts, RPC Task Scheduler staging, and a Sauron backdoor.