Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How Do I Check My iPhone for Malware: A Complete Guide

If your iPhone suddenly feels wrong, slower, hotter, or louder in the background, don't waste time hunting for a magic antivirus button. How do I check my iPhone for malware is the wrong question if you expect a desktop-style scan, because iOS doesn't work that way. The right question is, what did the attacker leave behind, and what changed in the device's behavior or configuration? That's the triage mindset security teams use on endpoints, and it fits iPhone incidents too.

The 14-Hour Recovery: Rethinking Healthcare Cyber Resilience

Ransomware recovery for healthcare IT depends on isolated recovery environments (IRE) and the ability to find clean data for patient safety. Jeremy Cathey shares insights on building cyber resilience by moving away from traditional disaster recovery toward a model that handles systemic cyberattacks. He details the three essential zones of an IRE: the clean room for forensics, the staging zone for validation, and the standby production environment where clinicians resume work.

Ransomware protection: how endpoint security and backup work together

Quick definition Ransomware protection combines two things that work at different points of an attack: endpoint protection software that detects and blocks ransomware before it encrypts data, and backup and disaster recovery solutions that let an organization restore its systems if an attack still gets through.

Atlanta's $17M Ransomware Attack: What Could Have Stopped It

In March 2018, the SamSam ransomware attack on the city of Atlanta became one of the most expensive ransomware incidents ever to hit a US local government. It remains a useful case study in what happens when an organization has no way to detect, stop or recover from ransomware in real time.

SparkKitty Malware: An Emerging Threat to Mobile Users

SparkKitty is a newly uncovered cross-platform information stealer, designed to exfiltrate sensitive data—particularly cryptocurrency wallet seed phrases—by leveraging advanced optical character recognition (OCR) techniques on both Android and iOS devices. The malware, discovered by Kaspersky in early 2024 and publicly detailed in June 2025, appears to be a direct evolution of a previous stealer known as SparkCat.

Why Flipping Cyber Defense Backwards Works

Standard incident response is failing to keep pace with long-term threat campaigns. Adam Karcher from the FBI explains why the most effective security teams run their operations as an inverted offensive strategy, leveraging continuous adversary emulation to stop intrusions before they begin. Watch the full video on our channel.

From Inbox to Encryption: How Ransomware Delivery Has Evolved

Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours. What the threat looks like in 2026 is fundamentally different. The email that starts the chain carries nothing dangerous. Instead, the ransomware arrives weeks later, launched by a completely different attacker. So, what can organizations do to protect themselves from these new threats?

The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

The JFrog Security Research team has discovered and disclosed a typosquatted NuGet package named Newtonsoftt.Json.Net. Note the double t and the.Net suffix. This package has been masquerading as the popular Newtonsoft.Json library while quietly shipping a trojanized fork. The trojan rigs Digitain, an online betting platform, and in later generations, exfiltrates rigged round results to an attacker-controlled server, utilizing the header X-Seq-ApiKey: theperfectheist2025.

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware

During June 2026, Arctic Wolf Labs investigated multiple intrusions during which threat actors exploited CVE-2026-0257 as a consistent initial access vector, rapidly transitioning from perimeter compromise to domain-wide Qilin ransomware encryption across distinct victim environments.

WannaCry Ransomware: Infection, Impact, and Prevention

WannaCry, also known as WannaCrypt, is a notorious ransomware strain that gained global attention in May 2017 due to its widespread and damaging impact. It belongs to the category of malware known as ransomware, which encrypts a victim’s files and demands a ransom payment, usually in cryptocurrency, in exchange for a decryption key that can unlock the files.

Building a More Secure Workplace Technology Environment

One weak password. One rushed click. One laptop left in a rideshare. That's all it can take to create a very real problem for your business. Strong workplace technology security is no longer just about locking down computers. It protects payroll, customer records, employee privacy, contracts, financial data, and the trust you've worked hard to earn.

How Aikido Intel detects malware and vulnerabilities first

TL;DR: Aikido Intel is a real-time supply chain intelligence feed. It detects both malware and vulnerabilities in open-source ecosystems. Aikido's world-class researchers maintain our LLM-powered pipeline to find malware and validate the most malicious cases by hand. The vulnerability detection system monitors package changes across ecosystems to catch and document vulnerabilities that don’t have CVEs assigned.

ClickFix Social Engineering is Now the Leading Malware Delivery Method

The ClickFix social engineering technique is now the top malware delivery method, according to a new report from ReliaQuest. These attacks trick users into copying a malicious command, then pasting it into a terminal and running it on their computers. “ClickFix remained the dominant delivery method this period and, for the first time, we observed it expand to macOS, delivering infostealers onto a platform many organizations still monitor less closely than Windows,” the researchers write.

Could your own AI agents run a ransomware attack?

Ransomware is evolving well beyond locking systems, and agentic AI is introducing a category of security risk most organizations are not yet equipped to handle. On The Cybersecurity Defenders Podcast, Behnaz Karimi, Senior Cybersecurity Analyst at Accenture and independent ransomware researcher, walks through what that shift actually looks like. The full conversation includes.

JADEPUFFER: How an Agentic Ransomware Attack Unfolded

In early July 2026, researchers at Sysdig published an analysis of what they assess to be the first documented case of agentic ransomware. The threat actor, which Sysdig calls JADEPUFFER, launched an extortion attack driven end to end by a large language model (LLM) rather than a conventional human-operated toolkit.

They Infiltrated the Infiltrators - And What They Found Was Unprecedented

Investigators have turned the tables on one of the world’s most elusive regimes. After a security firm hired a man calling himself "Joseph," a team of private investigators did what no one had done before: they infiltrated a North Korean remote worker cell from the inside. Head to our YouTube channel and watch the full episode of To Catch a Thief, Season 2.

LimeRat Malware: Delivery Techniques and Organizational Impact

Lime RAT stands out as an openly available and meticulously documented malware suite built on the.NET framework, boasting a multitude of capabilities that can be highly destructive when wielded proficiently. Its capacity to pilfer a wide array of valuable data, employ encryption for ransom purposes, or transform the targeted host into a basic-capability bot, combined with an easy-to-use control panel interface, positions it as a preferred choice for less experienced operators.

Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs

An initial access broker associated with the Payouts King ransomware group is using Microsoft Teams phishing to deploy a malicious Microsoft Edge web browser extension, according to researchers at Zscaler. Once the hackers have a foothold within an organization, they sell the access to the ransomware gang to conduct follow-on attacks.

How Do You Get Hacked With Zero Malware?

Everyone remembers WannaCry. WantToCry sounds like the same thing. It isn't. It encrypts your files remotely over SMB using nothing but stolen credentials and right now 1.5 million devices are sitting exposed on the public internet. In this episode we break down how remote ransomware works, why your antivirus and EDR never see it coming and what caught it in our Sophos telemetry.

Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry

A malicious release of @injectivelabs/sdk-ts, an npm package that pulls around 50,000 weekly downloads, shipped code that records wallet mnemonics and private keys as they are derived and ships them to an attacker-controlled endpoint. The bad version, 1.20.21, was live on npm for under an hour on June 8, 2026 before the maintainer noticed and published a clean fix.

Unmasking BitRAT's C2 over HTTPS

BitRAT is a potent and versatile Remote Access Trojan (RAT) commonly sold on underground forums. Its popularity stems from a robust feature set and an emphasis on stealth, allowing it to evade detection by hiding command-and-control (C2) communications over seemingly benign protocols. This makes traditional detection methods more challenging. By examining the subtle artifacts it leaves behind, even in encrypted traffic, defenders can expose these elusive threats.

Threat Actors to Watch: SafePay, FancyBear, and ShinyHunters

From a fast-scaling ransomware operator to a Russian state-sponsored espionage group now experimenting with LLM-powered malware, and a data extortion collective that has weathered arrests without slowing down, these three threat actors span the full spectrum of financially and geopolitically motivated cybercrime. CYJAX breaks down what each group does, why they matter, and what security teams should know.

Ransomware in the age of agentic AI with Behnaz Karimi [337]

Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learning pipelines, and autonomous agents.

Ep. 5: The Heists

In the decade after Sony, North Korea learned something fundamental: Destructive cyberattacks make headlines. Financial cyberattacks make money. One year after Sony, North Korea pulled off one of the most audacious bank heists in history and reshaped cybercrime in the process. Today, the regime has expanded those same tactics into billion dollar cryptocurrency heists and sprawling money laundering schemes designed to evade sanctions and bankroll the state – and its nuclear weapons program.

Identifying and detecting ScoutC2 malware

At Corelight Labs, our mission is to help organizations stay a step ahead of evolving threats. When our researchers came across Censys' detailed write-up on ScoutC2, a rapidly growing open-source command-and-control (C2) framework favored by threat actors, we knew we needed to bolster community defenses quickly.

What is a Ransomware Attack? Definition, Types & Prevention Strategies

Ransomware isn’t just a rising threat, it’s a daily reality for thousands of businesses around the world. These attacks are faster, smarter, and more damaging than ever, with global losses projected to reach $275 billion a year by 2031, according to Cybersecurity Ventures. Understanding how ransomware works is the first step toward stopping it. In this blog, we’ll break down how these attacks unfold and what you can do to defend your systems.

BlackMatter Ransomware Explained: Delivery Methods, Tactics, and Targets

Emerging in July 2021, BlackMatter is a ransomware-as-a-service (RaaS) platform that permits the developers of the ransomware to generate income through the actions of their cybercriminal associates, referred to as BlackMatter actors, who utilize it against targets. BlackMatter is potentially a reimagining of DarkSide, another RaaS that remained operational from September 2020 to May 2021.

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud" worm across npm and PyPI, npm account takeovers via expired recovery domains, and five concrete defenses — starting with searching your GitHub org for "tpcp-docs" right now.

Security Bulletin: GitHub Impersonation Deploys Information Stealer

Arctic Wolf Internal Security Operations (SecOps) recently identified a GitHub page impersonating Arctic Wolf to target our customers and prospects. The SecOps team immediately escalated these findings to our Threat Research team, who uncovered a complex attack chain subsequently deploying information-stealing malware. Arctic Wolf has since removed this fake GitHub page.

Vect and TeamPCP partner for ransomware campaigns

Counter Threat Unit (CTU) researchers investigated two interconnected threat groups known as Vect and TeamPCP. The two groups announced a formal operational partnership in late March 2026 to combine TeamPCP’s credential harvesting and data theft capabilities with Vect’s ransomware deployment infrastructure in a widespread campaign involving supply chain attacks and the extortion of multiple organizations.

Veil#Drop: Blogspot-Hosted PowerShell Loader

Veil#Drop is a sophisticated multi-stage malware delivery framework that combines social engineering, compromised websites, malicious JavaScript launchers, PowerShell download cradles, and trusted cloud-hosted infrastructure to deploy PureLog Stealer entirely in memory. The infection chain begins with a deceptively named JavaScript file masquerading as a document (e.g., transcript.pdf.js), which executes through Windows Script Host and launches PowerShell with execution policy bypasses enabled.

RubyGems supply chain attack: malware used as a credential exfiltration dead drop

Package registries have a well-known abuse pattern: attackers upload malicious packages, and unsuspecting developers install them. Our researchers just found the pattern working in reverse, in a RubyGems supply chain attack that turns the registry into a place to stash stolen data rather than deliver it.