ResolverRAT, a previously undocumented remote access trojan (RAT), is being used in phishing attacks on global healthcare and pharmaceutical groups, according to cybersecurity firm Morphisec. The malware is distributed through region-specific phishing emails and uses in-memory execution, making it hard to detect. Morphisec also highlighted similarities between the phishing infrastructure used in this campaign and the earlier Rhadamanthys and Lumma efforts.

SANS Stormcast Monday, November 3rd, 2025: Port 8530/8531 Scans; BADCANDY Webshells; Open VSX Security Improvements
Scans for WSUS: Port 8530/8531 TCP, CVE-2025-59287 We did observe an increase in scans for TCP ports 8530 and 8531. These ports are associated with

