A wave of cyberattacks exploiting vulnerabilities in Microsoft Internet Information Services (IIS) servers, employing BadIIS malware, was recently identified with links to Chinese-speaking groups. The attackers have manipulated SEO rankings, distributed malicious content, and redirected users to illegal gambling websites or malicious servers. Victims are spread across Asia, with instances beyond this region. The attacks were executed for financial gain, highlighting inadequacies in IIS server security.

Threat Actors Target MS-SQL Servers to Deploy ICE Cloud Scanner Malware
Threat actors are continuing to aggressively target Microsoft SQL (MS-SQL) servers in 2026, with new evidence showing the deployment of a scanner malware known as


