Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Pikabot Malware: Delivery Methods, Evasion, and Impact

Originating in early 2023, Pikabot emerged as a significant malware loader. Over the past year, ThreatLabz has diligently monitored its development and operational methods. Notably, there was a surge in Pikabot’s usage in the latter part of 2023, attributed to a BlackBasta ransomware affiliate adopting Pikabot post the FBI-led Qakbot takedown. However, Pikabot’s activity ceased shortly after Christmas 2023, with version 1.1.19 marking its endpoint.

Mini Shai-Hulud hits openapi-react-query-codegen: 10 malicious npm versions

On August 28, 2026, ten malicious versions of @7nohe/openapi-react-query-codegen were published to npm between 20:00 and 20:21 UTC. The package generates React Query hooks from an OpenAPI schema and draws roughly 150,000 weekly downloads. The latest tag pointed at the malicious 3.0.4 for the duration of the window. Eight of the ten releases carry a multi-stage loader that reaches for cloud, registry, and developer credentials. The attacker needed no stolen npm token and no hijacked maintainer account.

Does It Make Sense to Pay a Ransom? A C-Suite Guide to DevOps Resilience

When ransomware hits, decision makers face an impossible ultimatum: pay the ransom or lose business operations. In software development, data criticality also comes to the forefront. That’s because source code isn’t just some trivial data, but primary intellectual property and a revenue driver. Let’s see what’s exactly at stake and how you can minimize the risk of paying a ransom for your tech business.

ESP32 Marauder tutorial for WPA2 deauthentication and handshake capture

Wireless networks are often assumed to be secure once WPA2 is enabled. In practice, that assumption is only partly true. While WPA2 remains widely used and is not inherently broken, the real security of a wireless network depends heavily on how it is configured, how client devices behave, and how strong the Pre-Shared Key (PSK) actually is. As a result, the protocol label alone can sometimes create a misleading sense of security.

Dark Caracal Reloaded: New Malware, Same Hunting Grounds

Arctic Wolf Labs exposes Dark Caracal’s evolving tradecraft, linking 249 samples to two operational build profiles and a resilient Ethereum-based C2 architecture targeting Latin America. In June 2026, Arctic Wolf Labs investigated a targeted intrusion affecting a communications organization in Venezuela.

Attackers Use Vishing Attacks to Distribute New Android Malware

Attackers are distributing a new Android malware called “WindRelay” via phone-based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employees and instruct them to install a malicious app. In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.

'The Gentlemen' Profile: Why This Ransomware Group Wants In Before It Locks You Out

The Gentlemen is a financially motivated ransomware group that combines data theft with encryption to increase pressure on victims. They first came onto the threat scene in July 2025. Rather than relying on encryption alone, the group exfiltrates sensitive business data before locking files, leaving organizations to deal with both operational disruption and the risk of stolen information being exposed.

What Campaigns Like Grandoreiro Teach Us About Threat Detection

The recent Grandoreiro campaign detected by the WatchGuard Threat Lab team is a clear example of how today’s threats combine different techniques to make detection more difficult and operate more discreetly. In this case, the attack begins with a phishing email designed to persuade the user to click a link. From there, the victim is taken through several redirects and eventually downloads a compressed file from well-known services such as Dropbox or MediaFire.

Threat Actors to Watch: Akira and Storm-1175

From a ransomware-as-a-service group that can move from initial access to full encryption in under four hours, to a China-linked affiliate that has quietly pivoted to its own encryptor, these two threat actors show how mature the ransomware ecosystem has become. CYJAX breaks down what each group does, why they matter, and what security teams should know.