- Shai Hulud 2.0, now with a wiper flavorby Kaspersky on December 3, 2025 at 8:10 pm
Kaspersky researchers uncover a new version of the Shai Hulud npm worm, which is attacking targets in Russia, India, Brazil, China, and other countries, and has wiper features.
- Kaspersky Security Bulletin 2025. Statisticsby AMR on December 2, 2025 at 10:07 am
Kaspersky Security Bulletin contains statistics on various cyberthreats for the period from November 2024 to October 2025, which are based on anonymized data voluntarily provided by Kaspersky users via Kaspersky Security Network (KSN).
- To buy or not to buy: How cybercriminals capitalize on Black Fridayby Kaspersky on November 24, 2025 at 12:30 pm
How cybercriminals prepare for Black Friday: phishing, scams and malware targeting online shoppers and gamers, fake sales in spam and real sales on the dark web.
- IT threat evolution in Q3 2025. Non-mobile statisticsby AMR on November 19, 2025 at 10:00 am
The report presents key trends and statistics on malware that targets personal computers running Windows and macOS, as well as Internet of Things (IoT) devices, during the third quarter of 2025.
- Post-exploitation framework now also delivered via npmby Vladimir Gursky, Artem Ushkov on October 17, 2025 at 10:00 am
The npm registry contains a malicious package that downloads the AdaptixC2 agent onto victims’ devices, Kaspersky experts have found. The threat targets Windows, Linux, and macOS.
- SEO spam and hidden links: how to protect your website and your reputationby Anna Larkina on October 17, 2025 at 7:00 am
Are you seeing your website traffic drop, and security systems blocking it for pornographic content that is not there? Hidden links, a type of SEO spam, could be the cause.
- Massive npm infection: the Shai-Hulud worm and patient zeroby Vladimir Gursky, Dmitry Vinogradov on September 25, 2025 at 10:00 am
We dissect a recent incident where npm packages with millions of downloads were infected by the Shai-Hulud worm. Kaspersky experts describe the starting point for the source of the infection.
- Shiny tools, shallow checks: how the AI hype opens the door to malicious MCP serversby Mohamed Ghobashy on September 15, 2025 at 10:00 am
Kaspersky experts discuss the Model Context Protocol used for AI integration. We describe the MCP’s architecture, attack vectors and follow a proof of concept to see how it can be abused.
- Cookies and how to bake them: what they are for, associated risks, and what session hijacking has to do with itby Anna Larkina, Natalya Zakuskina on September 2, 2025 at 10:00 am
Kaspersky experts explain the different types of cookies, how to configure them correctly, and how to protect yourself from session hijacking attacks.
- Toxic trend: Another malware threat targets DeepSeekby Lisandro Ubiedo on June 11, 2025 at 10:00 am
Kaspersky GReAT experts discovered a new malicious implant: BrowserVenom. It enables a proxy in browsers like Chrome and Mozilla and spreads through a DeepSeek-mimicking phishing website.
Web Threats
We are an ethical website cyber security team and we perform security assessments to protect our clients.

















