Malware & Threats
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Hi, what are you looking for?
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out.
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word.
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems.
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees.
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion...
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data...
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.
A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer.
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members.
Other noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings...
The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command.