Skip to content

Derp | Security Research

Derp watches where malware calls home. Every day it counts the live command-and-control and distribution hosts behind each family, the victims ransomware crews name on their leak sites, the domains serving ClickFix lures, and the ones running rented phishing kits. When something is worth taking apart properly, the analysis goes in research.

Security News

  1. Path Traversal and Upload Path Tampering in Telerik UI for ASP.NET AJAXopens in a new tab

    malware.news

  2. Russian National Extradited Over Freelancer Platform Malware Campaignopens in a new tab

    Infosecurity Magazine

  3. TukTuk Framework Enables Credential Theft and EDR Evasion for Gentlemen Ransomwareopens in a new tab

    Cyber Security

  4. Gambling Goblin Hijacks Brazilian Websites for Gambling SEO Fraudopens in a new tab

    Infosecurity Magazine

  5. Public Exploit Targets Cleo Harmony JWT Authentication Bypassopens in a new tab

    Cyber Security

  6. Knight Office AiTM Kit Steals Microsoft 365 Sessions and Establishes Entra Persistenceopens in a new tab

    IT Security Guru

  7. Kimsuky Uses Seafood Purchase Lure to Deploy Backblaze B2-Backed Malwareopens in a new tab

    Lazarusholic Bluesky

  8. AI-Assisted Ransomware Attack Compromised Enterprise via Public APIopens in a new tab

    Unit 42

  9. ExfilSquad Extorts UK Institutions With Stolen Cloud and CRM Dataopens in a new tab

    malware.news

  10. International Operation Sinkholes Sality Botnet and Seizes Payload Domainsopens in a new tab

    Help Net Security

  11. SafePay Ransomware Abuses OneDrive for Stealthy Data Exfiltrationopens in a new tab

    malware.news

  12. Microsoft to Enable Memory Integrity by Default on Eligible Windows 11 PCsopens in a new tab

    Windowslatest

  13. Actively Exploited SonicWall SMA1000 Flaws Enable SSRF and Command Executionopens in a new tab

    BleepingComputer

  14. Counterfeit Software Installers Deliver Silver Fox-Like Malware Campaignopens in a new tab

    malware.news

  15. Nexus Dark-Web Service Sells 153 Million Driver’s License Scansopens in a new tab

    malware.news

  16. Ransomware Groups Recruit Insiders for Corporate Network Accessopens in a new tab

    Dark Reading

  17. Phishing Campaign Abuses Faronics Deploy to Install ScreenConnectopens in a new tab

    BleepingComputer

  18. Leaked Bauman Records Expose Russian Military Cyber Recruitment Pipelineopens in a new tab

    Gbhackers

  19. Critical JFrog Artifactory Authentication Bypass Exploited for Admin Tokensopens in a new tab

    Decipher Sc

  20. Malicious npm Dependency Chain Delivers Cross-Platform Remote-Access Trojanopens in a new tab

    Lazarusholic Bluesky

  21. Chameleon SEO Poisoning Drives Banking Phishing Pages Above Search Resultsopens in a new tab

    Knowbe4

  22. ClickFix Campaign Abuses ChatGPT Links to Deploy NetSupport Remote-Access Malwareopens in a new tab

    Cyber Security

  23. Active Exploitation of Sangoma Switchvox SQL Injection Enables RCEopens in a new tab

    Reddit Netsec

  24. Attackers Exploit Critical Langflow RCE to Harvest Cloud and SSH Credentialsopens in a new tab

    SecurityWeek

  25. Indian Data Broker Sells Unauthorized KYC Records via Telegram and APIopens in a new tab

    malware.news

  26. Chrome Web Store Permanently Removes Manifest V2 Extensionsopens in a new tab

    Thecybersecguru

  27. BREEZE COMET Targets Brazilian Financial Networks for Fraudulent Transfersopens in a new tab

    Mandiant

  28. Trojanized Exodus Wallet Installer Deploys Modular Memory-Resident RATopens in a new tab

    Huntress

  29. OEMPocalypse Exploit Chains Achieve Kernel Compromise on Major Android OEMsopens in a new tab

    malware.news

  30. Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attemptopens in a new tab

    The Record Media

  31. Rogue Free LLM Endpoint Captures Coding-Agent Context and Tool Accessopens in a new tab

    malware.news

  32. White House Launches Texas Water-System Cybersecurity Pilotopens in a new tab

    Cyberscoop

  33. Manic Android Trojan Relays Stolen Banking Data Through Nearby Devicesopens in a new tab

    Kaspersky

  34. Dependency Cooldowns Limit Exposure to Malicious Package Releasesopens in a new tab

    The New Stack

  35. Trojanized Packagist Themes Use FUNNULL-Hosted iPhone Spyware Chainopens in a new tab

    Socket

  36. Orova Claims Theft of 150,000 Cardiology Associates Patient Recordsopens in a new tab

    malware.news

  37. Global Ransomware Activity Reaches 2026 High With 894 July Victimsopens in a new tab

    Zdnet

  38. OpenClaw 2.0 Adds Credential, Plugin and AI-Agent Security Controlsopens in a new tab

    Cyber Security

  39. ValleyRAT Backdoor Delivered Through Trojanized QN Wallpaper Adwareopens in a new tab

    malware.news

  40. Spring Ring Uses Microsoft Teams Vishing to Pursue Domain Compromiseopens in a new tab

    Unit 42

  41. Nigerian Sextortion Suspects Extradited to Face Charges Linked to Teen Deathsopens in a new tab

    BleepingComputer

  42. China-Linked Fire Ant Abuses Trusted Infrastructure for Espionageopens in a new tab

    The Hacker News

  43. Fraudulent School Websites Target Students, Parents and Educatorsopens in a new tab

    malware.news

  44. Automated Bots Consume Nearly All git.kernel.org Trafficopens in a new tab

    Opennet

  45. TerminalFix ClickFix Campaign Establishes Reverse-Tunnel Access Through Compromised Hostsopens in a new tab

    malware.news

  46. McKesson Investigates Data Theft Claim After Third-Party Application Breachopens in a new tab

    malware.news

  47. OpenAPI React Query Codegen npm Releases Deliver Credential-Stealing Supply-Chain Malwareopens in a new tab

    StepSecurity

  48. Magecart Skimmers Abuse Stripe APIs and Ethereum Contracts for Payload Deliveryopens in a new tab

    Confiant

  49. KubeCap Identifies Excess Linux Capabilities in Kubernetes Workloadsopens in a new tab

    Linuxsecurity

  50. X Dismantles Suspected China-Linked Bot Farm Targeting AI Data-Center Debateopens in a new tab

    Foxbusiness

  51. CISA Flags Actively Exploited ownCloud, Linux Kernel and JFrog Artifactory Flawsopens in a new tab

    Security Affairs

  52. Root Backdoors Found in Globally Rebranded ZBT Router Firmwareopens in a new tab

    Heise

  53. Critical cPanel Flaw Lets Hosting Users Escalate to Root Server Controlopens in a new tab

    The Hacker News

  54. Critical Pre-Authentication RCE Flaws Expose WatchGuard Fireware VPNsopens in a new tab

    Csirt Italia

  55. CISA Finds Known Internet-Exposed Flaws Drive Most Damaging Compromisesopens in a new tab

    Security Online Info

  56. Log4Shell RCE in Apache Log4j Exposes Java Applicationsopens in a new tab

    Tenable Nessus Plugins

  57. Agentic AI Enables Rapid Enterprise Attacks and Expands Threat Actor Capabilityopens in a new tab

    Cyberscoop

  58. Dark-Web Marketplaces Sell Corporate Executive SSNs for $0.25opens in a new tab

    Cyber Security

  59. PaperCut NG/MF Zero-Day Exploited on Internet-Exposed Serversopens in a new tab

    BleepingComputer

  60. Manchester Airports Group Customer Data Stolen in Cybersecurity Incidentopens in a new tab

    BleepingComputer

  61. AI Coding Agents Installed Unclaimed Packages Referenced in llms.txt Filesopens in a new tab

    Arstechnica Security

  62. Criminal Forums Commercialize AI Tools for Ransomware and Spear-Phishingopens in a new tab

    Knowbe4

  63. CISA Flags Six Actively Exploited NetScaler, SQL Server, Linux, and Red Hat Flawsopens in a new tab

    Infosecurity Magazine

  64. Misconfigured AD CS Templates Enable Domain Privilege Escalationopens in a new tab

    Guidepoint Security

  65. Polymorphic JavaScript Phishing Page Evades Detection and Can Hang Browsersopens in a new tab

    malware.news

  66. ICS Malware Blocking Falls to Four-Year Low as Email Threats Riseopens in a new tab

    Securelist

Trackers

Latest Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.