🚨 Acaban de liberar una de las mayores bases de datos de malware en GitHub.
Se llama Malware Research Hub y contiene miles de muestras recopiladas durante más de 50 años para que investigadores y profesionales de ciberseguridad puedan analizarlas en entornos controlados.
Esto es lo que incluye:
→ 2.699 muestras de malware de diferentes épocas
→ Especímenes de familias como Stuxnet y LockBit
→ Un catálogo forense con 80 familias documentadas
→ Herramientas para investigadores y analistas de seguridad
→ Muestras aisladas y cifradas para reducir el riesgo de ejecución accidental
Lo más importante:
No estamos hablando de simulaciones ni ejemplos creados para un curso.
El repositorio contiene malware real y debe tratarse únicamente en laboratorios aislados y siguiendo estrictamente sus reglas de contención.
Es un recurso orientado al análisis, investigación y formación práctica en ciberseguridad.
Repo 👇
urlscan Pro University is officially LIVE!
Master urlscan search through hands-on challenges - from basic to advanced
Discover typosquat detection, threat verdicts, and phish hunting.
Solve challenges, submit flags, track your progress.
https://t.co/QXV9KYMxD1
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector:
💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820)
🧰New tools, including #Troy backdoor
🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure
Read More :
https://t.co/GDI2Ze7CRH
🔥 We “hired” Lazarus APT remote workers — and uncovered their toolkit.
@BirminghamCyber & @north_scan used #ANYRUN Sandbox to capture weeks of Famous Chollima activity inside a fake startup.
👀 How not to let a spy in? See full story and videos: https://t.co/IOUZmZEjJQ
Microsoft has failed to properly patch RoguePlanet (CVE-2026-50656), ShieldBreak, a PoC that demonstrates a full bypass to the previous patch is now public.
https://t.co/YFfn559z6o
The PoC works with the latest August 2026 patch
🛠️ Tool Tuesday: SoftPerfect NetScan
A legitimate network scanner, and a threat-actor favorite. Across our cases, actors use NetScan to map hosts, shares, and open ports right before lateral movement, sometimes launching RDP straight from its interface.
🔎 Hunt tip: alert on netscan.exe spawning mstsc.exe, and on scanner activity from non-IT hosts.
See it across real intrusions 👉 https://t.co/Dvyc8uB8TE
Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations. https://t.co/ON4JqUlygl
DeadLock's recovery ecosystem combines a messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims. As defenders, law enforcement, and industry partners increase pressure on cybercriminal ecosystems, threat actors are being forced to adapt their operations and invest in new ways to maintain resilience.
The ransomware employs double extortion tactics and has impacted organizations across multiple sectors and global regions. Get detections, mitigation guidance, and deeper insights into DeadLock's infrastructure, recovery ecosystem, and encryptor design from this Microsoft Threat Intelligence blog post.
🛡️ The Average Breach Goes Undetected for 207 Days
That's 207 days of data loss, lateral movement, and damage — before you even know about it. Proactive threat hunting changes that…
CyberHawk Threat Intel · https://t.co/MLTkJOzvgR
#cyberhawkthreatintel#cybersecurity#infosec