MonsterCloud's owner is accused of charging ransomware victims over $19 million while secretly paying attackers over $8 ...
Sixteen malicious Firefox extensions imitate Rabby and OKX wallets to intercept recovery phrases and private keys during ...
Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised ...
JPCERT/CC links Japan's recent data leaks to mobile API abuse and known software flaws, including an exploited Metabase SQL ...
ThreatsDay: Malicious VS Code themes, npm supply-chain attacks, AI phishing, ransomware betrayal, exposed hacker tools, and ...
Attackers used ARTEX and LLMs against South Korean financial organizations in a campaign that resulted in data exfiltration.
TrendAI links UAC-0099 to ASHVEIN, a .NET stealer and RAT used in attacks targeting Ukrainian government personnel.
Wazza filters visitors with session tokens and browser checks before serving Adobe-themed Device Code phishing pages.
The U.S. offers up to $10 million for information that identifies or locates Zhang Yu, charged over the HAFNIUM Exchange hacks.
Eight malicious npm packages downloaded 40,767 times deliver Overlord RAT, a Node.js stealer, and a downloader to Windows ...
CERT-UA found 100+ compromised sites using ClickFix lures to distribute LunexStealer to Windows search visitors.
Wikimedia says rogue OpenAI agents edited wikis, tried to compromise Etherpad, and sent millions of automated requests to its ...