Skip to content

Derp | Security Research

Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.

Security News

  1. CIA Cyber Intelligence Enabled Capture of Venezuela's Nicolás Maduroopens in a new tab

    malware.news

  2. Russian Developer Extradited Over $14.6 Million Bank Account-Takeover Schemeopens in a new tab

    Cyberscoop

  3. Microsoft Fixes 973 Flaws Including Two Exploited Windows Privilege Escalation Zero-Daysopens in a new tab

    malware.news

  4. Compromised Flutter Package Carries XCSSET Malware in Example Projectopens in a new tab

    Aikido Dev

  5. ChatGPT Sandbox Flaw Enabled Cross-Account Gmail Data Exfiltrationopens in a new tab

    Cryptika

  6. WeWorm Zero-Click WeChat Calls Could Hijack Accounts Across iOS and Androidopens in a new tab

    Help Net Security

  7. Social-Engineering Ring Accused of Stealing $240 Million in Bitcoinopens in a new tab

    SecurityWeek

  8. UTA-2026-024 Disables Endpoint Protection and Seizes Windows Domain Controlopens in a new tab

    Cyber Security

  9. ClickFix Campaigns Abuse Browser Scripts to Steal Cryptocurrency and Credentialsopens in a new tab

    malware.news

  10. Critical FreeIPA Flaw Chain Lets Anonymous LDAP Clients Gain Administrator Accessopens in a new tab

    The Hacker News

  11. N-able N-central Flaws Let Unauthenticated Attackers Create System Administratorsopens in a new tab

    Rapid7

  12. Qubes OS qvm-copy-to-vm Flaw Enabled Command Execution in Dom0opens in a new tab

    Opennet

  13. MacSync macOS Stealer Uses ClickFix Lures to Exfiltrate Credentialsopens in a new tab

    malware.news

  14. Panzer RaaS Targets Italian Firms With VMware ESXi Encryption Capabilityopens in a new tab

    Cyber Security

  15. ShinyHunters Breach Exposes 6.39 Million Odido and Ben Customer Recordsopens in a new tab

    Cyber Security

  16. AD RMS SLC Key Compromise Can Expose All Protected Documentsopens in a new tab

    Huntress

  17. Microsoft Fixes AD CS Flaw Allowing Local SYSTEM Privilege Escalationopens in a new tab

    Msrc Microsoft

  18. BigBear 2.0 AiTM Service Stole Microsoft 365 Credentials and MFA Sessionsopens in a new tab

    malware.news

  19. Bimbo Bakeries Employee Data Stolen Through Oracle EBS Zero-Dayopens in a new tab

    Cyber Security

  20. Mathspace Reporting-System Breach Exposes Data of 1.08 Million Usersopens in a new tab

    Cyber Security

  21. ConnectWise Warns of ScreenConnect File-Transfer Security Flawopens in a new tab

    Cyber Security

  22. BYOTC Hijacks Trusted Windows Clients to Abuse Privileged Driversopens in a new tab

    Cyber Security

  23. DPRK Cyber Program Split Into Six Lazarus-Linked Operational Clustersopens in a new tab

    Infosecurity Magazine

  24. Fake Minecraft Lithium Mod Delivers Myth Stealer RATopens in a new tab

    Cyber Security

  25. OpenVPN 2.7.7 Patches Remote DoS and Six Windows Security Flawsopens in a new tab

    Cyber Security

  26. N-able Patches Pre-Authentication RCE in N-centralopens in a new tab

    Mkd Cirt

  27. UK Cyber Bill Faces Calls for Executive Liability and AI Shutdown Powersopens in a new tab

    Register Security

  28. Russian GRU-Linked HOOKEDGE Backdoor Targets European Government and Defense Bodiesopens in a new tab

    Cyber Security

  29. vlt 1.0 Launches npm-Compatible Registry With Malware Blockingopens in a new tab

    Infoq

  30. Kimsuky Evolves GitHub PAT-Based LNK Campaign With AI-Generated Decoysopens in a new tab

    Lazarusholic Bluesky

  31. Critical Frontend Admin WordPress Plugin Flaw Enables Administrator Takeoveropens in a new tab

    ThreatAft

  32. StyleSmuggler Zero-Day Enables Unauthenticated RCE in Magento Storesopens in a new tab

    Cyber Security

  33. Windows PE TLS Callbacks Execute Code Before the Program Entry Pointopens in a new tab

    malware.news

  34. OpenAI-Identified Agents Used German Wiki to Coordinate Sandbox Evasionopens in a new tab

    Register Security

  35. US and UK Coordinate Takedowns of Southeast Asian Scam Centersopens in a new tab

    The Record Media

  36. PostGREShell Flaw Lets Replication Users Take Over PostgreSQL Serversopens in a new tab

    The Hacker News

  37. DPRK-Linked Actors Deploy HAProxy Backdoor and CurlRAT Against South Korean Firmsopens in a new tab

    The Hacker News

  38. Empty SMTP Envelope Sender Bypasses Microsoft 365 Direct Send Blockingopens in a new tab

    SC World

  39. DaVita Pays $15 Million to Settle Ransomware Data-Breach Lawsuitopens in a new tab

    malware.news

  40. TP-Link Archer AX55 Flaws Enable LAN Code Execution and Admin Password Decryptionopens in a new tab

    Cyber Security

  41. Microsoft Teams Will Obscure QR Codes in External Messages to Thwart Phishingopens in a new tab

    Cyber Security

  42. Botnet Takedowns Shrink DDoS Fleets as Attack Intensity Reaches 2.3 Tbit/sopens in a new tab

    Itpro

  43. Toy Ghouls Deploys HiveMQ and Matrix-Based Windows Backdoorsopens in a new tab

    malware.news

  44. PEEP Browser RAT Masquerades as Smart Bookmarks Chrome Extensionopens in a new tab

    SOCRadar

  45. Attackers Abuse Radmin and UltraVNC to Turn Korean Hosts Into Proxy Serversopens in a new tab

    malware.news

  46. ShinyHunters Vishing Attack Hits Jack Henry Internal Systemsopens in a new tab

    Cyberveille

  47. SSRF Exploitation of EC2 IMDSv1 Credentials Led to Unauthorized Amazon Bedrock Useopens in a new tab

    Aws Security

  48. Exposed Robobox Infrastructure Links AI-Assisted Malware Toolkit to Coruna iOS C2opens in a new tab

    Netaskari Substack

  49. CrySyS Lab Introduces EMBeD Benchmark for IoT Malware Detectionopens in a new tab

    malware.news

  50. Leaked AWS IAM Key Used to Steal and Resell Paid Bedrock AI Accessopens in a new tab

    Cyber Security

  51. DPRK-Linked Contagious Interview Uses Trojanized macOS Installers to Deploy OtterCookieopens in a new tab

    Lazarusholic Bluesky

  52. Signed Shift Browser Adware Fingerprints Hosts Before Installing Browser Payloadopens in a new tab

    Heimdalsecurity Com Threat Center

  53. MECCHA CHAMELEON Steam Workshop Maps Enabled Two-Click RCEopens in a new tab

    Aikido Dev

  54. Wyden Urges NSA Warning That Single-Hop VPNs Enable Traffic Correlationopens in a new tab

    malware.news

  55. Goja TypedArray Memory Corruption Enables RCE in Zendesk and Nucleiopens in a new tab

    Slcyber

  56. Path Traversal and Upload Path Tampering in Telerik UI for ASP.NET AJAXopens in a new tab

    malware.news

  57. Russian National Extradited Over Freelancer Platform Malware Campaignopens in a new tab

    Infosecurity Magazine

  58. TukTuk Framework Enables Credential Theft and EDR Evasion for Gentlemen Ransomwareopens in a new tab

    Cyber Security

  59. Gambling Goblin Hijacks Brazilian Websites for Gambling SEO Fraudopens in a new tab

    Infosecurity Magazine

  60. Public Exploit Targets Cleo Harmony JWT Authentication Bypassopens in a new tab

    Cyber Security

  61. Knight Office AiTM Kit Steals Microsoft 365 Sessions and Establishes Entra Persistenceopens in a new tab

    IT Security Guru

  62. Kimsuky Uses Seafood Purchase Lure to Deploy Backblaze B2-Backed Malwareopens in a new tab

    Lazarusholic Bluesky

  63. AI-Assisted Ransomware Attack Compromised Enterprise via Public APIopens in a new tab

    Unit 42

  64. ExfilSquad Extorts UK Institutions With Stolen Cloud and CRM Dataopens in a new tab

    malware.news

  65. International Operation Sinkholes Sality Botnet and Seizes Payload Domainsopens in a new tab

    Help Net Security

  66. SafePay Ransomware Abuses OneDrive for Stealthy Data Exfiltrationopens in a new tab

    malware.news

  67. Microsoft to Enable Memory Integrity by Default on Eligible Windows 11 PCsopens in a new tab

    Windowslatest

Trackers

Latest Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.