CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf V...
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf V...
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. ...
The attack involved injecting a dependency on a malicious package, proc-macro1, which impersonated the popular proc-macro2 crate.
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases tha...
Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat I...
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compil...
The campaign, observed in late July 2026, begins with compromised WordPress websites injected with obfuscated ErrTraffic JavaScript.
Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsof...
A malicious Google Apps Script sidebar leads to payloads for both macOS and Windows.
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as w...
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact inf...
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC...
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices...
A supply-chain campaign targeting OpenClaw has shown how threat actors can turn autonomous AI agents into persuasive malware-delivery intermediaries. Rather ...
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point ...
Threat actors are increasingly abusing the popularity of generative AI brands to distribute malware, turning trusted names such as Claude, ChatGPT and Micros...
Aeternum operators are abusing Polygon smart contracts as a decentralized dead-drop resolver, allowing malware to retrieve and rotate command-and-control (C2...
eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra
The compromised LAN driver, hosted on a legacy support page, allowed the Asruex backdoor to operate with administrator-level permissions.