Skip to content

Derp | Security Research

Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.

Security News

  1. Dark-Web Marketplaces Sell Corporate Executive SSNs for $0.25opens in a new tab

    Cyber Security

  2. PaperCut NG/MF Zero-Day Exploited on Internet-Exposed Serversopens in a new tab

    BleepingComputer

  3. Manchester Airports Group Customer Data Stolen in Cybersecurity Incidentopens in a new tab

    BleepingComputer

  4. AI Coding Agents Installed Unclaimed Packages Referenced in llms.txt Filesopens in a new tab

    Arstechnica Security

  5. Criminal Forums Commercialize AI Tools for Ransomware and Spear-Phishingopens in a new tab

    Knowbe4

  6. CISA Flags Six Actively Exploited NetScaler, SQL Server, Linux, and Red Hat Flawsopens in a new tab

    Infosecurity Magazine

  7. Misconfigured AD CS Templates Enable Domain Privilege Escalationopens in a new tab

    Guidepoint Security

  8. Polymorphic JavaScript Phishing Page Evades Detection and Can Hang Browsersopens in a new tab

    malware.news

  9. ICS Malware Blocking Falls to Four-Year Low as Email Threats Riseopens in a new tab

    Securelist

  10. Critical WatchGuard Windows Agent Flaws Enable Unauthenticated SYSTEM-Level RCEopens in a new tab

    Cyber Security

  11. Coordinated Intrusion Disrupts Remote Monitoring at Minnesota Water Utilitiesopens in a new tab

    Optiv

  12. NSA Recruits Former TAO Operators to Rebuild Elite Hacking Unitopens in a new tab

    malware.news

  13. FBI Disrupts QTFY Proxy Network Used to Breach U.S. Federal Agenciesopens in a new tab

    Cyberscoop

  14. Attackers Target Exposed AI Control Planes for Credentials and Cryptominingopens in a new tab

    malware.news

  15. Critical Unauthenticated RCE Chain in SENAITE.CORE JSON APIopens in a new tab

    Cvefeed High Severity

  16. Tortoiseshell Deploys C++ Backdoor and Reverse SSH Tunneling Infrastructureopens in a new tab

    The Record Media

  17. LLM-Integrated Malware and Agentic AI Ransomware Emergeopens in a new tab

    Zdnet Zero Day

  18. Log4j2 MarshalledObject Deserialization Bypass Enables Conditional RCEopens in a new tab

    Thecybersecguru

  19. Suspected Chinese-Speaking Operator Breaches Philippine Nuclear and Naval Organizationsopens in a new tab

    Reddit Netsec

  20. China-Linked Espionage Exploits Edge Devices to Target High-Value Organizationsopens in a new tab

    Tenable

  21. Ivanti EPMM Zero-Days Exploited Amid Broad Edge Infrastructure Targetingopens in a new tab

    Sentinelone

  22. Fake Claude Desktop Ads Deliver SectopRAT and Disable Microsoft Defenderopens in a new tab

    Cyber Security

  23. Dark Caracal Targets Venezuelan Communications Organization With Ethereum-Based C2opens in a new tab

    malware.news

  24. SonicWall NetExtender Linux Flaws Enable Root-Level Arbitrary File Writesopens in a new tab

    Cyber Security

  25. OpenAI Bans Russian Accounts Operating Fake Think Tank Influence Campaignopens in a new tab

    Toms Hardware

  26. MuddyWater Hides Dindoor Backdoor Execution in Signed Deno Runtimeopens in a new tab

    Cyber Security

  27. CrashFix Campaign Uses Fake Chrome Repair to Deploy ModeloRATopens in a new tab

    malware.news

  28. OpenStack Keystone Flaws Let Delegated Tokens Escape Project Scopeopens in a new tab

    Oss Security Mailing List

  29. Critical Unauthenticated File Write in DB-GPT Skill Upload Enables RCEopens in a new tab

    Cvefeed High Severity

  30. NVIDIA NemoClaw Flaw Lets Malicious Websites Persistently Poison Local AI Modelsopens in a new tab

    Cvefeed High Severity

  31. CISA Red Team Exposes Government SOC Failure and Water-Sector Resilienceopens in a new tab

    Cyberscoop

  32. OpenRGB Server Flaws Enable Arbitrary File Overwrite and Remote Root Compromiseopens in a new tab

    Oss Security Mailing List

  33. Seoul National University Hospital Faces Scrutiny Over Cybersecurity Reporting After 830,000-Record Breachopens in a new tab

    malware.news

  34. AI Agent Swarm Breached Asian Government Systems and Stole Personnel Recordsopens in a new tab

    Cyber Security

  35. INTERPOL Operation Jackal IV Disrupts West African Cybercrime Networksopens in a new tab

    Help Net Security

  36. RecruitTrap Mobile Phishing Campaign Targets Enterprise Credentialsopens in a new tab

    Infosecurity Magazine

  37. Malicious npm Packages Used to Host Fake Cloudflare CAPTCHA Phishing Pagesopens in a new tab

    The Hacker News

  38. Actively Exploited Oracle WebLogic and HTTP Server Flaw Enables Full Compromiseopens in a new tab

    Register Security

  39. Palo Alto Finds Most AI-Enabled Malware Remains Experimental or AI-Brandedopens in a new tab

    Unit 42

  40. EvilTokens Device Code Phishing Uses Notion Lures to Steal Microsoft 365 Tokensopens in a new tab

    Cyber Security

  41. WeedHack Infostealer Persists Through Fake Minecraft Sites and SEO Poisoningopens in a new tab

    Security Affairs

  42. Chrome 152 Adds Connection Allowlists and Enhanced Safe Browsing Warningsopens in a new tab

    Chrome Developer

  43. sg3_utils `sg_inq --export` Flaw Enables Root Command Execution via udev Injectionopens in a new tab

    Redhat Access

  44. libXfont2 Font Server Flaws Enable X Server Privilege Escalationopens in a new tab

    Redhat Access

  45. Void Arachne Pushes Winos 4.0 via Trojanized AI, VPN, and Telegram Installersopens in a new tab

    Trendai Security

  46. PolinRider Campaign Hijacked GitHub Maintainer Accounts to Push Malware to npmopens in a new tab

    Opensourcemalware

  47. Treasury Sanctions Iran-Linked Hackers and Crypto Addresses in Economic Outcastopens in a new tab

    Trm Labs

  48. US Sanctions Iranian Hackers Linked to Critical Infrastructure Intrusionsopens in a new tab

    The Record Media

  49. miniOrange WordPress SSO Flaws Exploited for Administrator Account Takeoveropens in a new tab

    SC World

  50. PE Metadata and Icons Can Be Faked to Masquerade Unsigned Windows Malwareopens in a new tab

    malware.news

  51. Ascent Nursing Facilities Disclose Vendor-Linked PHI Breach Affecting Residentsopens in a new tab

    malware.news

  52. AI Agent Flaws Expose RCE, Sandbox Escape, and Supply-Chain Attack Pathsopens in a new tab

    The New Stack

  53. Microsoft Teams Adds Policy to Automatically Block External Meeting Botsopens in a new tab

    Cyber Security

  54. Fake Microsoft SysScan Sites Push Victims to Remove Antivirusopens in a new tab

    malware.news

  55. Malicious Firefox Add-ons Stole Crypto Wallet Seed Phrases and Browser Credentialsopens in a new tab

    Bitdefender

  56. Kimsuky Used AI-Built Chrome Extension and Remote Tools to Steal Gmail Dataopens in a new tab

    Cyber Security

  57. WebKitGTK Use-After-Free Flaw Exposes RHEL Systems to Possible Remote Code Executionopens in a new tab

    Bugzilla Redhat

  58. AliExpress Used Silent Web Audio Fingerprinting to Track Shoppersopens in a new tab

    Register Security

  59. PavinLoader Linked to ClickFix, Fake Downloads, and RenPy Malware Campaignsopens in a new tab

    malware.news

  60. Hugo SSRF Flaw Lets `resources.GetRemote` Reach Internal and Metadata Endpointsopens in a new tab

    Cvefeed High Severity

  61. AnonyMousKIT Used AI Phishing to Steal Apple IDs and Unlock Stolen Devicesopens in a new tab

    SOCRadar

  62. Fake GTA VI ISO Torrent Used to Deliver Malware and Disable Defensesopens in a new tab

    Heise

  63. WebKitGTK Permissions Flaw Lets Malicious Websites Leak Sensitive Dataopens in a new tab

    Redhat

  64. Critical JSONata RCE Flaws Let Crafted Expressions Escape Sandboxesopens in a new tab

    Cvefeed High Severity

  65. Broad Spring Advisory Wave Exposes 91 CVEs Across Framework and Related Projectsopens in a new tab

    malware.news

  66. Trojanized npm Packages Deploy RedC2 Linux Backdoor on Importopens in a new tab

    The Hacker News

  67. OWASP Warns Malicious AI Skills Enable Large-Scale Agent and Dependency Hijacksopens in a new tab

    Dark Reading

  68. iAuthFlow V2 Phishing Kit Adds Passkeys for Persistent Account Takeoveropens in a new tab

    SecurityWeek

  69. Agent Tesla v4 Uses BEC Lures and In-Memory Injection to Evade Detectionopens in a new tab

    Cyber Security

  70. Scalper Bots Flood DDR5 Retail Pages as Memory Shortages Drive Price Spikesopens in a new tab

    Toms Hardware

  71. LPAC COM Capability Check Bypassed for In-Process MTA Componentsopens in a new tab

    Huntandhackett

  72. Microsoft Entra ID RCE Exploited via Unsafe Deserializationopens in a new tab

    The Hacker News

Trackers

Latest Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.