Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Malware that hid itself on infected systems and disabled antivirus protection.
Inside the JDownloader Supply-Chain Attack: An r77 Rootkit Bot That Kills Your Antivirus. Malware that hid itself on infected systems and disabled antivirus protection.
The EtherRAT malware family was first reported by Sysdig back in December 2025.
This DFIR flash alert analyzes the EtherRAT malware family, which began with Linux exploitation via CVE-2025-55182. A Windows variant campaign was later reported, with activity dating back to the prior December.
The DFIR Report's flash alert details EtherRAT, a malware family first reported by Sysdig after exploitation of CVE-2025-55182 against Linux servers. Later campaigns used a Windows variant, with evidence extending back to December 2025.
The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers.