Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscapeMalware NewsletterClingSTUN Linux Backdoor Abuses Public STUN Infrastructure UAC-0277: ClickFix on compromised websites to spread LUNEXSTEALERMALFEX – A malicious npm postinstall no advisory has caught for fourteen months Canto incognito: tracking the PoeLLM malwareTensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and AustraliaSleep, Beacon, Steal, Repeat – The Story of P7 DarkSword Variant Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer Never Deleted, Only Re-Pointed: Inside the 17,600-Repo FakeGit Fleet That Re-Arms OvernightThe phone was compromised before the user turned it on: the rise of Midnight Mimosa ORCAGen: Orchestrating Context-Aware Malware Deception with RAG-Guided Generative AIMARS: Malware Analysis with Rule-Based Scoring of LLM Claims An IoT Malware Detection Framework Based on Large Language Models and Deep Learning TechniquesAn Explainable Attention-Enhanced Deep Learning Model for Memory-Forensic Malware DetectionFollow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)