Malware & Threats
Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access.
Hi, what are you looking for?
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access.
Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware.
Nimbus Manticore has continued its operations during and after the US military campaign against Iran.
Register to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every...
Other noteworthy stories that might have slipped under the radar: CISA contractor exposes credentials, Mythos testing and new features, Huawei router flaw triggered telecom...
A compromised maintainer account was used to publish malicious package versions across the @antv namespace.
Don't miss this virtual event as we explore how to cut through alert fatigue, leverage AI and unified platforms to accelerate investigations, and apply...
Fox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software.
Attackers are increasingly abusing Microsoft’s decades-old MSHTA utility to stealthily deliver stealers, loaders, and persistent malware through phishing, fake software downloads, and LOLBIN-based attack...
At least one threat actor has adopted the recently released malware source code in attacks against NPM developers.
Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters hacks...
The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.
Salt Typhoon has hit an energy entity in Azerbaijan. Twill Typhoon has targeted Asian entities with an updated RAT.
More than 500 packages were pushed during the attack, but the target appears to have been RubyGems itself rather than users.
CRPx0 is a complex, stealthy malware campaign that targets macOS and Windows systems, and appears to have Linux capabilities in development.
Over 400 malicious versions of 170 packages were published as part of the new Mini Shai-Hulud campaign.
Other noteworthy stories that might have slipped under the radar: US gov targets 72-hour patch cycles, malware uses Windows Phone Link to steal OTPs,...
The malware framework targets web applications and cloud environments, including AWS, Docker, Kubernetes, and more.
The software developer has identified the impacted systems, removed potentially compromised files, and validated installation packages.
The persistent, evasive implant provides remote access, surveillance, and credential exfiltration capabilities.