Malware Newsletter
UAC-0145 Primary Compromise Vectors as of July 2026
AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results
UAC-0099: LUNCHPOKE, BURNYBEAR, updated to MATCHBOIL.V2 and using Notepad++ 8.8.3
Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
Symmetric Dual-Domain Prototype Adaptation for Few-Shot Image-Based Malware Classification
(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure
Taming the Security-Energy Paradox: A Green AI Approach to Optimized Android Malware Detection
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
