DOUBLECUP’s PNG Payload, (Mon, Aug 24th)

Malware Makers Get Creative, But Still Leave Clues Behind A new variant of the DOUBLECUP malware has made headlines in cybersecurity circles for its use of what appears to be steganography – hiding malicious code within an image file. However, upon closer inspection, it turns out that this particular strain doesn’t actually employ real steganography … Read more

Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund

Anthropic’s ambitious push to make its advanced AI models more accessible to cybersecurity defenders has just taken a significant leap forward. The company is expanding access to its Mythos 5 model, which offers powerful capabilities for detecting and mitigating cyber threats, while also unveiling a $35 million open source fund to support the security of … Read more

ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)

A Devastating Malware Campaign Hits Global Networks, Leaving a Trail of Wipeout In a coordinated attack that’s sending shockwaves through the cybersecurity community, hackers have unleashed a devastating malware campaign that’s already infected thousands of computers worldwide. The assault, which began on Sunday evening, has left a trail of destroyed data and crippled networks in … Read more

ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)

A Massive Spam Campaign Targets Global Businesses with Malware-Laced Emails A recent surge in spam emails has been detected by cybersecurity experts at SANS ISC, potentially putting millions of businesses worldwide at risk. The campaign, which began on Monday, August 24th, is characterized by sophisticated phishing tactics and the use of malware to compromise corporate … Read more

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android Malware Evolution: A Growing Threat to Mobile Security A new version of the highly sophisticated Android malware, ToxicPanda, has emerged with alarming features that allow it to evade detection and wreak havoc on infected devices. The latest variant, dubbed ToxicPanda 2.0, has expanded its targeting scope to 349 applications and now includes … Read more

ToxicPanda Android malware uses VPN permissions to block Google Play

ToxicPanda Malware Evolves, Bypassing Security Measures on Android Devices A new version of the ToxicPanda malware has emerged, equipped with advanced features that allow it to evade security checks and install its payload undetected. The malware, which targets 349 applications across 16 countries, has been distributed through Amazon AWS-hosted buckets, according to mobile security company … Read more

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The US Postal Service has quietly finalized new regulations that grant the federal government sweeping powers over mail-in ballots for voters, sparking concerns about election integrity and voter suppression. The move comes despite multiple lower courts striking down similar rules as unconstitutional. At issue are changes to postal services’ handling of mail-in ballots, which would … Read more

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows Named Pipes Under Attack: A Growing Security Concern In recent months, cybersecurity experts have sounded the alarm over a growing threat to Windows systems: unsecured named pipes. These pipes, used for communication between applications on the same computer, are increasingly being exploited by attackers. With potentially devastating consequences, it’s essential for administrators and developers … Read more