- Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware setby Omar Amin on September 1, 2026 at 7:00 am
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
- ValleyRAT masquerading as adwareby Pavel Bukhtenko on August 31, 2026 at 10:00 am
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
- Threat landscape for industrial automation systems. Q2 2026by Kaspersky ICS CERT on August 27, 2026 at 10:05 am
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
- Exploits and vulnerabilities in Q2 2026by Alexander Kolesnikov on August 26, 2026 at 10:00 am
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
- The invisible passenger in your carby Dmitry Kalinin on August 21, 2026 at 8:00 am
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It’s delivered through legitimate software for DoFun head units.
- APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkitby Fareed Radzi on August 14, 2026 at 9:00 am
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
- Armored Likho expands its cyber-espionage toolkitby Konstantin Isakov on August 13, 2026 at 8:00 am
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
- Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participantsby Kaspersky on August 11, 2026 at 12:00 pm
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.
- Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selectionby GReAT on August 11, 2026 at 10:00 am
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
- IT threat evolution in Q2 2026. Non-mobile statisticsby AMR on August 10, 2026 at 10:00 am
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
Securelist
We are an ethical website cyber security team and we perform security assessments to protect our clients.

















