SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

UAC-0145 Primary Compromise Vectors as of July 2026  

SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor  

AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware  

Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel  

HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels  

The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results  

UAC-0099: LUNCHPOKE, BURNYBEAR, updated to MATCHBOIL.V2 and using Notepad++ 8.8.3  

Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis? 

Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI  

Symmetric Dual-Domain Prototype Adaptation for Few-Shot Image-Based Malware Classification

Small, Free, and Effective: Orchestrating Open-Weight Small Language Models to Outperform Single LLM for Malware Analysis

(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure

Taming the Security-Energy Paradox: A Green AI Approach to Optimized Android Malware Detection

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter