MalwareTips Newswire

Security updates, independent AV tests and useful news for the MalwareTips community.
Check Point Research ·

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional downloaders and […] The post Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect appeared first on Check Point Research.
Read original article
Check Point Research ·

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were […] The post 17th August – Threat Intelligence Report appeared first on Check Point Research.
Read original article
Check Point Research ·

The State of Ransomware Q2 2026

For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but […] The post The State of Ransomware Q2 2026 appeared first on Check Point Research.
Read original article
Zero Day Initiative ·

The August 2026 Security Update Review

I’ve successfully survived Hacker Summer Camp, and I have returned with a new outlook on patch density. When even Linus Torvalds says that huge updates are the “new normal”, it’s time to readjust what we consider a true bug apocalypse. This month’s release is thankfully smaller than last months, but still huge by historical standards. Take a break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for August 2026 For the first part of the August release, Adobe released five bulletins addressing 51 unique CVEs in Adobe ColdFusion, Commerce, Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic. Here’s this month’s overview table: Adobe Patches for August 2026 Adobe Patches for August 2026 Bulletin ID Product CVE Count Highest Severity Highest CVSS Exploited Deployment Priority APSB26-90 Adobe ColdFusion 15 Critical 10.0 No 1 APSB26-123 Adobe Campaign Classic 3 Critical 10.0 No 1 APSB26-92 Adobe Commerce 7 Critical 9.1 No 2 APSB26-94 Adobe Lightroom Classic 11 Critical 8.6 No 3 APSB26-111 Content Credentials SDK 15 Critical 7.5 No 3 TOTAL 5 bulletins 51 If you’re running Campaign Classic, that’s your priority. Not only is it a deploym
Read original article
Check Point Research ·

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially […] The post Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack appeared first on Check Point Research.
Read original article
Load more