Israeli security researchers scanned over 6,000 corporate domains and found 120 llms.txt/llms-full.txt files—AI-readable site guides similar to robots.txt—referencing unregistered code packages or domains. When the researchers claimed those names and set up beacons, dozens of organizations, including Fortune 500 firms, triggered phone-home connections within hours, with process logs showing AI coding agents like Claude, Codex, and Hermes had automatically fetched and executed the unowned code. At least one misconfigured site was already pointing to live malware.
arstechnica.com
· 2026-08-27
Security researchers have identified GoCaracal, a previously undocumented modular malware framework used by the Dark Caracal cyber espionage group. The tool expands the group's ability to steal data from victims and maintain persistent access to compromised systems.
darkreading.com
· 2026-08-26
Security firm Huntress published findings from investigations conducted throughout 2026 in which it helped organizations confirm they had unknowingly hired North Korean operatives posing as IT staff. Cases included an Australian healthcare firm that flagged three employees suspected of impersonating Chinese nationals, plus two separate incidents in the financial services sector uncovered in August. Huntress noted these DPRK-linked workers have grown more skilled and active, blending into IT teams while funneling wages back to the regime and potentially planting malware or stealing data.
darkreading.com
· 2026-08-26
Researchers have identified that operators behind the BadBox click-fraud botnet are now targeting Android-powered vehicle head units, exploiting built-in update mechanisms to push malicious software onto the devices. This marks an expansion of the botnet's reach beyond streaming boxes and smart TVs into automotive infotainment systems.
darkreading.com
· 2026-08-26
Researchers have identified a new loader tool called WordlistLoader that disguises malicious code as ordinary text files, such as word lists, to slip past security defenses. It's being used in ClickFix-style attacks—where victims are tricked into manually executing commands—to deploy the Amatera infostealer, a malware family that has been rapidly gaining traction among cybercriminals.
darkreading.com
· 2026-08-24
Researchers have identified a sophisticated malware toolkit called SynkLoader that revives an old screen-hijacking technique to steal passwords while also incorporating a range of newer capabilities. The malware supports multiple languages and functions as a multitool, suggesting it could serve as a precursor to ransomware deployment.
darkreading.com
· 2026-08-24
Security researchers report that ToxicPanda, an Android banking trojan, has been updated with new capabilities that extend its reach beyond individual financial apps. The revised malware now poses risks to broader enterprise environments, not just personal banking credentials.
darkreading.com
· 2026-08-24
Kaspersky researchers discovered a new Android malware strain in June 2026 that spreads through the built-in update mechanisms of Android-based automotive head units, marking the first documented infection chain targeting this device category. The app installs silently with no interface, functioning as a multi-stage downloader designed for ad fraud and building a proxy botnet. Kaspersky attributes the campaign with high confidence to MoYu Group, an actor tied to the previously known BADBOX botnet.
securelist.com
· 2026-08-23
A file claiming to be a 113GB build of Grand Theft Auto VI has been spreading on torrent sites following recent leaks of the game. Independent analysts who examined the download say it is almost entirely padded with empty zeroes and contains a hidden 50KB malicious payload rather than actual game code. The malware reportedly tries to disable Windows Defender protections and kill security processes once executed.
tomshardware.com
· 2026-08-23
Zimperium researchers found a new version of the ToxicPanda Android malware that requests VPN service permissions to intercept and control device network traffic, allowing it to cut off communication with Google Play and Play Protect. The updated trojan, spread via Amazon AWS-hosted buckets, now supports 167 remote commands and phishing overlays for 349 banking, crypto, and e-wallet apps across 16 countries, plus a separate module that harvests PINs from 140 financial apps.
bleepingcomputer.com
· 2026-08-23