Pierluigi Paganini
November 30, 2025

Malware Newsletter
Analysis of ShadowPad Attack Exploiting WSUS Remote Code Execution Vulnerability (CVE-2025-59287)
Shai-Hulud 2.0 Supply Chain Attack: 25K+ npm Repos Exposed
Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications
Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix
ShadowV2 Casts a Shadow Over IoT Devices
ClickFix Gets Creative: Malware Buried in Images
Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine
Shai Hulud Launches Second Supply-Chain Attack: Zapier, ENS, AsyncAPI, PostHog, Postman Compromised
Inside the GitHub Infrastructure Powering North Korea’s Contagious Interview npm Attacks
Inside the GitHub Infrastructure Powering North Korea’s Contagious Interview npm Attacks
Bloody Wolf: A Blunt Crowbar Threat To Justice
Synthetic Data: AI’s New Weapon Against Android Malware
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
