Malware & Threats
Published through five accounts, the extensions appear part of a coordinated campaign based on shared C&C infrastructure.
Hi, what are you looking for?
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
Published through five accounts, the extensions appear part of a coordinated campaign based on shared C&C infrastructure.
Researchers found adware capable of killing cybersecurity products and pushing more dangerous payloads to infected systems.
Download links were replaced by a Russian-speaking threat actor to distribute a recently emerged malware named STX RAT.
The malware mimics the legitimate Anthropic installation, relies on DLL sideloading, and cleans up after itself.
Focused on persistence, the botnet does not engage in widespread infection and avoids blacklisted IPs and critical infrastructure entities.
The APT28 threat group exploited vulnerable TP-Link and MikroTik routers to conduct adversary-in-the-middle (AitM) attacks.
Hackers published 36 NPM packages posing as Strapi plugins to execute shells, escape containers, and harvest credentials.
Other noteworthy stories that might have slipped under the radar: Symantec vulnerability, anti-ClickFix mechanism added to macOS, FBI hack classified as major incident.
Using automated scanning and the Nexus Listener collection framework, the hackers compromised over 750 systems.
The malware can spy on victims, steal their information, and make configuration changes on devices.
The malware steals credentials, installs a malicious browser extension, and can spread via USB drives.
Licensed malware with built-in persistence and automation enables attackers to continuously siphon credentials, session data, and cryptocurrency assets.
Two malicious versions of the popular SDK were uploaded to the PyPI registry, targeting Windows, macOS, and Linux.
The infection chain includes a fake CAPTCHA page, a Bash script, a Nuitka loader, and the Python-based infostealer.
Hambardzum Minasyan of Armenia has been accused of being involved in the development and administration of the infostealer malware.
The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$.
The FBI has published an alert describing the malware used by Iranian government hackers.
Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser.
The medtech giant has been working on restoring systems affected by the cyberattack conducted by the Handala hackers.
The botnet has increased its activity, peaking at 15,000 exploitation attempts per day, and taking a more targeted approach.