MacSync’s New Infection Chain Shows How Mac Malware Is Becoming More Sophisticated
A newly observed MacSync campaign shows a marked evolution in macOS-focused crimeware, replacing relatively simple AppleScript-driven delivery with layered b...
A newly observed MacSync campaign shows a marked evolution in macOS-focused crimeware, replacing relatively simple AppleScript-driven delivery with layered b...
Discover how Bring Your Own Vulnerable Driver (BYOVD) tactics evolved from lone-operator tricks into a commercialized, tiered EDR-killer service economy.
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutlesh...
Manifold Security found placeholder domains cited in 359,000 GitHub files and 349 AI agent skills serving cloaked scam…
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware...
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.
A threat actor tracked as Red Heron has exploited the critical Gitea remote code execution vulnerability CVE-2026-60004 to steal source-code repositories, es...
Kiteworks has urged customers worldwide to temporarily shut down their servers after receiving credible law-enforcement intelligence that a threat actor may ...
A new demonstration shows how a locally hosted, uncensored AI model can help generate a Windows LSASS credential-dumping utility that reportedly evaded endpo...
Microsoft has uncovered a destructive Azure campaign linked to Storm-3168, also known as JADEPUFFER, in which attackers abused compromised service principals...
The breach was discovered on Thursday evening when security systems detected unauthorized transfers.
EfficientIP Research Labs identified potential .cyou domains on June 9 that were later registered and began resolving to IP addresses on July 2.
The compromised GitHub Actions were originally disabled on May 18, 2026, after being found to execute malicious code that harvested sensitive credentials fro...
The flaw resided in Cloudflare's use of thin provisioning for container disks, where deleted container blocks were returned to a shared pool without being wi...
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities ind...
AI exposes old access problems faster, turning leaked credentials and standing trust into bigger risks.
Kiteworks’ CISO cited “credible threat intelligence from law enforcement” for the urgent alert.
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credit...
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the acti...