Fixed Intel
Shield

Malware & Threats

Malware analysis, threat intelligence, and emerging cyber threats

New 'Zombie ZIP' technique lets malware slip past security tools
BleepingComputer
Malware & Threats

New 'Zombie ZIP' technique lets malware slip past security tools

A new technique dubbed "Zombie ZIP" helps conceal payloads in compressed files specially created to avoid detection from security solutions such as antivirus and endpoint detection and response (EDR) products.

BleepingComputerMar 10, 20263m11
Microsoft releases Windows 10 KB5078885 extended security update
BleepingComputer
Malware & Threats

Microsoft releases Windows 10 KB5078885 extended security update

Microsoft has released the Windows 10 KB5078885 extended security update to fix the March 2026 Patch Tuesday vulnerabilities, including 2 zero-days and an issue that prevent some devices from shutting down.

BleepingComputerMar 10, 20263m10
Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
BleepingComputer
Malware & Threats

Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws

Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.

BleepingComputerMar 10, 202610m15
Windows 11 KB5079473 & KB5078883 cumulative updates released
BleepingComputer
Malware & Threats

Windows 11 KB5079473 & KB5078883 cumulative updates released

Microsoft has released Windows 11 KB5079473 and KB5078883 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.

BleepingComputerMar 10, 20266m14
HPE warns of critical AOS-CX flaw allowing admin password resets
BleepingComputer
Malware & Threats

HPE warns of critical AOS-CX flaw allowing admin password resets

Hewlett Packard Enterprise (HPE) has patched multiple security vulnerabilities in the Aruba Networking AOS-CX operating system, including several authentication and code execution issues.

BleepingComputerMar 10, 20263m10
Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys
BleepingComputer
Malware & Threats

Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys

Microsoft is rolling out passkey support for Microsoft Entra on Windows devices, adding phishing-resistant passwordless authentication via Windows Hello.

BleepingComputerMar 10, 20262m10
New KadNap botnet hijacks ASUS routers to fuel cybercrime proxy network
BleepingComputer
Malware & Threats

New KadNap botnet hijacks ASUS routers to fuel cybercrime proxy network

A newly discovered botnet malware called KadNap is targeting ASUS routers and other edge networking devices to turn them into proxies for malicious traffic.

BleepingComputerMar 10, 20263m10
The New Turing Test: How Threats Use Geometry to Prove 'Humanness'
BleepingComputer
High
Malware & Threats
78/10

The New Turing Test: How Threats Use Geometry to Prove 'Humanness'

Malware is evolving to evade sandboxes by pretending to be a real human behind the keyboard. The Picus Red Report 2026 shows 80% of top attacker techniques now focus on evasion and persistence, including geometry-based cursor tests and CPU timing checks.

LummaC2Financial ServicesHealthcare
BleepingComputerMar 10, 20267m10
CISA: Recently patched Ivanti EPM flaw now actively exploited
BleepingComputer
High
Malware & Threats
78/10

CISA: Recently patched Ivanti EPM flaw now actively exploited

CISA flagged a high-severity Ivanti Endpoint Manager (EPM) vulnerability as actively exploited in attacks and ordered U.S. federal agencies to patch systems within three weeks.

GovernmentFederal Agencies
BleepingComputerMar 10, 20263m10
Microsoft to enable Windows hotpatch security updates by default
BleepingComputer
Malware & Threats

Microsoft to enable Windows hotpatch security updates by default

Microsoft will turn on hotpatch security updates by default for all eligible Windows devices managed through Microsoft Intune and the Microsoft Graph API, beginning with the May 2026 Windows security update.

BleepingComputerMar 10, 20263m10
APT28 hackers deploy customized variant of Covenant open-source tool
BleepingComputer
Malware & Threats

APT28 hackers deploy customized variant of Covenant open-source tool

The Russian state-sponsored APT28 threat group is using a custom variant of the open-source Covenant post-exploitation framework for long-term espionage operations.

BleepingComputerMar 10, 20263m10
Microsoft Teams phishing targets employees with A0Backdoor malware
BleepingComputer
Malware & Threats

Microsoft Teams phishing targets employees with A0Backdoor malware

Hackers contacted employees at financial and healthcare organizations over Microsoft Teams to trick them into granting remote access through Quick Assist and deploy a new piece of malware called A0Backdoor.

BleepingComputerMar 9, 20263m13