SECURITY Affairs’ Malware Newsletter Round 115, published on 20 September 2026, is a collection of links to recent malware research and reporting rather than a single incident report. It highlights alleged activity involving a range of threats, including a Linux rootkit linked to a campaign exploiting a Gitea n-day vulnerability, a malicious Twitch browser extension reportedly exposing 30,000 users’ OAuth tokens, and Chrome and Windows zero-day exploitation attributed to multiple Chinese threat actors.
Other featured reports cover an MQTT-based infection-brokering operation in Asia, Iranian cyber targeting of dissidents, activists and journalists, SpiceRAT infrastructure associated with energy and government targets in Central Asia, and the SparroWock backdoor.
The roundup also links to research on a Brevo supply-chain attack said to have affected more than 100,000 WordPress websites, an AI-related technique for turning poisoned skills into malware droppers, the RatHat Android threat targeting credentials and bank accounts, and the KREMLIN browser extension, which reportedly impersonates Chrome integrity checks to steal banking sessions.
Several academic papers on malware detection and analysis are included, but the newsletter provides no further evidence, technical detail, affected-version information or mitigation guidance for these individual claims.