SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 66

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape————————————————————————————————————————————-Malware Newsletter[Ransomware and Cyber Extortion in Q3 2025](https://reliaquest.com/blog/threat-spotlight-ransomware-and-cyber-extortion-in-q3-2025)[Investigating active exploitation of CVE-2025-10035 GoAnywhere Managed File Transfer vulnerability](https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/)[XWorm V6: Exploring Pivotal Plugins](https://www.trellix.com/blogs/research/xworm-v6-exploring-pivotal-plugins/)[ClayRat: A New Android Spyware Targeting Russia](https://zimperium.com/blog/clayrat-a-new-android-spyware-targeting-russia)[Security Evaluation of Android apps in budget African Mobile Devices](https://arxiv.org/abs/2509.18800)[RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits](https://www.trendmicro.com/en_us/research/25/j/rondodox.html)[175 Malicious npm Packages Host Phishing Infrastructure Targeting 135+ Organizations](https://socket.dev/blog/175-malicious-npm-packages-host-phishing-infrastructure)[DDoS Botnet Aisuru Blankets US ISPs in Record DDoS](https://krebsonsecurity.com/2025/10/ddos-botnet-aisuru-blankets-us-isps-in-record-ddos/)[New Stealit Campaign Abuses Node.js Single Executable Application](https://www.fortinet.com/blog/threat-research/stealit-campaign-abuses-nodejs-single-executable-application)[New cyber threats: who and how hostile groups attack](https://cip.gov.ua/ua/news/novi-kiberzagrozi-kogo-i-yak-atakuyut-vorozhi-ugrupovannya)[Quantum Computing Methods for Malware Detection](https://arxiv.org/abs/2510.06803)[Cyber Warfare During Operation Sindoor: Malware Campaign Analysis and Detection Framework](https://arxiv.org/abs/2510.04118)[A Railway Mobile Terminal Malware Detection Method Based on SE-ResNet](https://www.mdpi.com/2076-3417/15/19/10760)[Zero-Day Ransomware Attack Detection Using Static Portable Executable Header Features](https://www.mdpi.com/2076-3417/15/19/10576)Follow me on Twitter: [@securityaffairs](https://twitter.com/securityaffairs) and [Facebook](https://www.facebook.com/sec.affairs) and [Mastodon](https://infosec.exchange/@securityaffairs)[Pierluigi Paganini](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)([SecurityAffairs](http://securityaffairs.co/wordpress/) — hacking, [newsletter](https://securityaffairs.com/182960/malware/security-affairs-malware-newsletter-round-65.html))

Related Tags:
NAICS: 54 – Professional

Scientific

Technical Services

NAICS: 517 – Telecommunications

NAICS: 541 – Professional

Scientific

Technical Services

NAICS: 518 – Computing Infrastructure Providers

Data Processing

Web Hosting

Related Services

NAICS: 51 – Information

Blog: Security Affairs

Phishing

Associated Indicators: