#then


Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

Aug 26, 2026 // 11:20

An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches […]

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

Aug 5, 2026 // 10:59

An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber […]

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Jul 25, 2026 // 21:50

A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of […]

GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

Jul 8, 2026 // 15:02

An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken […]

LeakNet Ransomware spreads through hacked websites using ClickFix. It then loads Deno directly into memory.

Mar 18, 2026 // 13:25

The LeakNet ransomware group is now using a social engineering trick called ClickFix, spread through hacked websites, to get into systems. Instead of relying on […]