Skip to content

Derp | Security Research

Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.

Security News

  1. OpenAPI React Query Codegen npm Releases Deliver Credential-Stealing Supply-Chain Malwareopens in a new tab

    StepSecurity

  2. Magecart Skimmers Abuse Stripe APIs and Ethereum Contracts for Payload Deliveryopens in a new tab

    Confiant

  3. X Dismantles Suspected China-Linked Bot Farm Targeting AI Data-Center Debateopens in a new tab

    Foxbusiness

  4. CISA Flags Actively Exploited ownCloud, Linux Kernel and JFrog Artifactory Flawsopens in a new tab

    Security Affairs

  5. Root Backdoors Found in Globally Rebranded ZBT Router Firmwareopens in a new tab

    Heise

  6. Critical cPanel Flaw Lets Hosting Users Escalate to Root Server Controlopens in a new tab

    The Hacker News

  7. Critical Pre-Authentication RCE Flaws Expose WatchGuard Fireware VPNsopens in a new tab

    Csirt Italia

  8. CISA Finds Known Internet-Exposed Flaws Drive Most Damaging Compromisesopens in a new tab

    Security Online Info

  9. Log4Shell RCE in Apache Log4j Exposes Java Applicationsopens in a new tab

    Tenable Nessus Plugins

  10. Agentic AI Enables Rapid Enterprise Attacks and Expands Threat Actor Capabilityopens in a new tab

    Cyberscoop

  11. Dark-Web Marketplaces Sell Corporate Executive SSNs for $0.25opens in a new tab

    Cyber Security

  12. PaperCut NG/MF Zero-Day Exploited on Internet-Exposed Serversopens in a new tab

    BleepingComputer

  13. Manchester Airports Group Customer Data Stolen in Cybersecurity Incidentopens in a new tab

    BleepingComputer

  14. AI Coding Agents Installed Unclaimed Packages Referenced in llms.txt Filesopens in a new tab

    Arstechnica Security

  15. Criminal Forums Commercialize AI Tools for Ransomware and Spear-Phishingopens in a new tab

    Knowbe4

  16. CISA Flags Six Actively Exploited NetScaler, SQL Server, Linux, and Red Hat Flawsopens in a new tab

    Infosecurity Magazine

  17. Misconfigured AD CS Templates Enable Domain Privilege Escalationopens in a new tab

    Guidepoint Security

  18. Polymorphic JavaScript Phishing Page Evades Detection and Can Hang Browsersopens in a new tab

    malware.news

  19. ICS Malware Blocking Falls to Four-Year Low as Email Threats Riseopens in a new tab

    Securelist

  20. Critical WatchGuard Windows Agent Flaws Enable Unauthenticated SYSTEM-Level RCEopens in a new tab

    Cyber Security

  21. Coordinated Intrusion Disrupts Remote Monitoring at Minnesota Water Utilitiesopens in a new tab

    Optiv

  22. NSA Recruits Former TAO Operators to Rebuild Elite Hacking Unitopens in a new tab

    malware.news

  23. FBI Disrupts QTFY Proxy Network Used to Breach U.S. Federal Agenciesopens in a new tab

    Cyberscoop

  24. Attackers Target Exposed AI Control Planes for Credentials and Cryptominingopens in a new tab

    malware.news

  25. Critical Unauthenticated RCE Chain in SENAITE.CORE JSON APIopens in a new tab

    Cvefeed High Severity

  26. Tortoiseshell Deploys C++ Backdoor and Reverse SSH Tunneling Infrastructureopens in a new tab

    The Record Media

  27. LLM-Integrated Malware and Agentic AI Ransomware Emergeopens in a new tab

    Zdnet Zero Day

  28. Log4j2 MarshalledObject Deserialization Bypass Enables Conditional RCEopens in a new tab

    Thecybersecguru

  29. Suspected Chinese-Speaking Operator Breaches Philippine Nuclear and Naval Organizationsopens in a new tab

    Reddit Netsec

  30. China-Linked Espionage Exploits Edge Devices to Target High-Value Organizationsopens in a new tab

    Tenable

  31. Ivanti EPMM Zero-Days Exploited Amid Broad Edge Infrastructure Targetingopens in a new tab

    Sentinelone

  32. Fake Claude Desktop Ads Deliver SectopRAT and Disable Microsoft Defenderopens in a new tab

    Cyber Security

  33. Dark Caracal Targets Venezuelan Communications Organization With Ethereum-Based C2opens in a new tab

    malware.news

  34. SonicWall NetExtender Linux Flaws Enable Root-Level Arbitrary File Writesopens in a new tab

    Cyber Security

  35. OpenAI Bans Russian Accounts Operating Fake Think Tank Influence Campaignopens in a new tab

    Toms Hardware

  36. MuddyWater Hides Dindoor Backdoor Execution in Signed Deno Runtimeopens in a new tab

    Cyber Security

  37. CrashFix Campaign Uses Fake Chrome Repair to Deploy ModeloRATopens in a new tab

    malware.news

  38. OpenStack Keystone Flaws Let Delegated Tokens Escape Project Scopeopens in a new tab

    Oss Security Mailing List

  39. Critical Unauthenticated File Write in DB-GPT Skill Upload Enables RCEopens in a new tab

    Cvefeed High Severity

  40. NVIDIA NemoClaw Flaw Lets Malicious Websites Persistently Poison Local AI Modelsopens in a new tab

    Cvefeed High Severity

  41. CISA Red Team Exposes Government SOC Failure and Water-Sector Resilienceopens in a new tab

    Cyberscoop

  42. OpenRGB Server Flaws Enable Arbitrary File Overwrite and Remote Root Compromiseopens in a new tab

    Oss Security Mailing List

  43. Seoul National University Hospital Faces Scrutiny Over Cybersecurity Reporting After 830,000-Record Breachopens in a new tab

    malware.news

  44. AI Agent Swarm Breached Asian Government Systems and Stole Personnel Recordsopens in a new tab

    Cyber Security

  45. INTERPOL Operation Jackal IV Disrupts West African Cybercrime Networksopens in a new tab

    Help Net Security

  46. RecruitTrap Mobile Phishing Campaign Targets Enterprise Credentialsopens in a new tab

    Infosecurity Magazine

  47. Malicious npm Packages Used to Host Fake Cloudflare CAPTCHA Phishing Pagesopens in a new tab

    The Hacker News

  48. Actively Exploited Oracle WebLogic and HTTP Server Flaw Enables Full Compromiseopens in a new tab

    Register Security

  49. Palo Alto Finds Most AI-Enabled Malware Remains Experimental or AI-Brandedopens in a new tab

    Unit 42

  50. EvilTokens Device Code Phishing Uses Notion Lures to Steal Microsoft 365 Tokensopens in a new tab

    Cyber Security

  51. WeedHack Infostealer Persists Through Fake Minecraft Sites and SEO Poisoningopens in a new tab

    Security Affairs

  52. Chrome 152 Adds Connection Allowlists and Enhanced Safe Browsing Warningsopens in a new tab

    Chrome Developer

  53. sg3_utils `sg_inq --export` Flaw Enables Root Command Execution via udev Injectionopens in a new tab

    Redhat Access

  54. libXfont2 Font Server Flaws Enable X Server Privilege Escalationopens in a new tab

    Redhat Access

  55. Void Arachne Pushes Winos 4.0 via Trojanized AI, VPN, and Telegram Installersopens in a new tab

    Trendai Security

  56. PolinRider Campaign Hijacked GitHub Maintainer Accounts to Push Malware to npmopens in a new tab

    Opensourcemalware

  57. Treasury Sanctions Iran-Linked Hackers and Crypto Addresses in Economic Outcastopens in a new tab

    Trm Labs

  58. US Sanctions Iranian Hackers Linked to Critical Infrastructure Intrusionsopens in a new tab

    The Record Media

  59. miniOrange WordPress SSO Flaws Exploited for Administrator Account Takeoveropens in a new tab

    SC World

  60. PE Metadata and Icons Can Be Faked to Masquerade Unsigned Windows Malwareopens in a new tab

    malware.news

  61. Ascent Nursing Facilities Disclose Vendor-Linked PHI Breach Affecting Residentsopens in a new tab

    malware.news

  62. AI Agent Flaws Expose RCE, Sandbox Escape, and Supply-Chain Attack Pathsopens in a new tab

    The New Stack

  63. Microsoft Teams Adds Policy to Automatically Block External Meeting Botsopens in a new tab

    Cyber Security

  64. Fake Microsoft SysScan Sites Push Victims to Remove Antivirusopens in a new tab

    malware.news

  65. Malicious Firefox Add-ons Stole Crypto Wallet Seed Phrases and Browser Credentialsopens in a new tab

    Bitdefender

  66. Kimsuky Used AI-Built Chrome Extension and Remote Tools to Steal Gmail Dataopens in a new tab

    Cyber Security

  67. WebKitGTK Use-After-Free Flaw Exposes RHEL Systems to Possible Remote Code Executionopens in a new tab

    Bugzilla Redhat

  68. AliExpress Used Silent Web Audio Fingerprinting to Track Shoppersopens in a new tab

    Register Security

  69. PavinLoader Linked to ClickFix, Fake Downloads, and RenPy Malware Campaignsopens in a new tab

    malware.news

  70. Hugo SSRF Flaw Lets `resources.GetRemote` Reach Internal and Metadata Endpointsopens in a new tab

    Cvefeed High Severity

  71. AnonyMousKIT Used AI Phishing to Steal Apple IDs and Unlock Stolen Devicesopens in a new tab

    SOCRadar

  72. Fake GTA VI ISO Torrent Used to Deliver Malware and Disable Defensesopens in a new tab

    Heise

  73. WebKitGTK Permissions Flaw Lets Malicious Websites Leak Sensitive Dataopens in a new tab

    Redhat

Trackers

Latest Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.