North Korean hackers behind the Contagious Interview campaign compromised over 30,000 devices worldwide, targeting crypto specialists and web designers to steal $10.7 million from more than 7,000 cryptocurrency wallets.
A campaign exploits SEO-optimized fake LastPass Authenticator GitHub repositories to distribute a new information stealer named Rapuncel.
Attackers compromised Brevo by stealing a Cloudflare API key and injecting malicious scripts into Brevo and its customers' websites, resulting in malware distribution via a supply-chain attack.
RatHat is a newly discovered Android malware that incorporates an AI-powered subsystem enabling attackers to remotely control compromised devices, streamlining exploitation actions.
An attacker hijacked an AI coding assistant session to distribute the Shai-Hulud worm within approximately 100 internal code repositories at a SaaS provider, resulting in theft of repository secrets and source code.
Iranian state-linked hackers are using the CHOSEN BRICK Windows malware to conduct surveillance on activists, dissidents, and journalists worldwide, enabling persistent spying and data collection.
US, UK, and Dutch agencies report Iran's intelligence uses Windows malware controlled via Telegram to spy on dissidents and journalists globally, targeting sensitive communications and recordings.
A China-linked espionage group exploits a critical vulnerability in Tencent's Sogou Input Method to deliver GrayRabbit backdoor malware, posing risks to users and enterprises.
Anthropic has disrupted a Russian state-sponsored threat actor's campaign that used AI to accelerate malware redevelopment and evade detection, marking an evolution in cyber espionage.
The China-linked threat group UNC3569 exploited a vulnerability in Sogou Input Method on Windows to deploy the GRAYRABBIT backdoor, allowing attackers full control of the affected user's machine.
JSCeal malware is a sophisticated JavaScript-based threat that bypasses Google authentication by stealing session cookies and uses advanced obfuscation to evade detection.
Over 5,400 small-business websites have been compromised to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain, using blockchain to evade detection.
Researchers identify BraZetsu, a Python-based Windows malware that enables Initial Access Brokers to commercialize compromised systems as marketplace inventory.
A Russian national has been indicted in the US for a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware, representing significant cybercrime against remote workers.
A surge of Guildma (Astaroth) malware infections is spreading through Brazilian Portuguese phishing emails, posing risks through data theft and stealthy behavior.
Microsoft warns of TerminalFix malware that exploits Windows Terminal and PowerShell via fake CAPTCHA prompts to create persistent reverse tunnels on compromised systems.
Researchers discovered 19 malicious Chrome and Edge browser extensions that steal cryptocurrency wallet secrets, indicating a coordinated campaign.
The StopAndProtect campaign uses nearly 2,000 compromised WordPress sites worldwide to distribute malware and collect stolen data, impacting web infrastructure security.
Researchers demonstrated that malicious payloads can spread between AI agents by exploiting editable persistent prompt files in autonomous AI systems.
Over 737 fake VPN and proxy extensions on the Chrome Web Store routed user traffic through SOCKS5 proxies controlled by a single entity, posing serious privacy and security risks.
CERT-UA reports Sandworm subgroup UAC-0145 targets Ukrainian IT workers with fake job interviews to deploy malware via a malicious VPN tool.
North Korea’s APT group Kimsuky has implemented an offline AI infrastructure that advances their phishing tactics and automates malware development by integrating AI with internal document search and malware creation tools.
A campaign distributing nearly 800 malicious npm packages with typo-squatted AI-generated names delivers a powerful RAT and infostealer targeting Windows, Mac, and Linux environments, posing a significant threat to developers and enterprises using npm packages.
The ChainDrop malware has compromised over 1,300 npm packages, impacting software supply chain security with billions of downloads monthly.
Talos analyzed prompt logs from various AI applications used by threat actors to understand their evolving tactics, revealing increased sophistication in leveraging cloud-based AI for malicious activities.
The DOUBLECUP loader uses ClickFix attacks to embed malware within PNG images cached by browsers on Windows and macOS, complicating detection.
A suspected Chinese-speaking threat actor has targeted Central Asian government organizations with OctLurk and SilkLurk malware since January 2025, impacting healthcare, research, and government sectors.
The Russian threat group Midnight Blizzard's Storm-2945 sub-cluster has compromised hospitality sign-in portals worldwide since May 2026, delivering malware and stealing traveler credentials.
North Korean threat actors have launched a sophisticated macOS malvertising campaign using fake update prompts to deliver crypto-stealing malware as part of the ongoing Contagious Interview operation.
Iranian state-backed group Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers in attacks across the Middle East, Africa, and South Asia, enhancing stealth and covert activity.
CERT-UA has identified a campaign where a fake Notepad++ plugin delivers MATCHBOIL.V2 malware, linked to the Russia-aligned UAC-0099 threat group targeting Windows systems.
Nearly 7,600 malicious GitHub repositories were discovered distributing the SmartLoader malware, leveraging cloned projects and fake profiles to deceive users.
North Korean threat actors linked to the Contagious Interview campaign employ steganography within SVG flag images in fake coding challenges to deliver multi-stage OTTERCOOKIE-aligned malware.
Seven malicious npm packages in the Vite ecosystem use a four-tier blockchain-based command-and-control infrastructure to deploy RAT malware, expanding the ChainVeil supply chain threat.
The OkoBot malware framework deploys more than 20 payloads aimed at stealing cryptocurrency wallet seed phrases, credentials, and sensitive data, posing a notable threat to individuals and enterprises.
Researchers revealed TuxBot v3 Evolution, an IoT botnet framework apparently developed with help from a large language model, highlighting emerging AI-assisted malware creation risks.
A malicious version of the Jscrambler npm package containing infostealer malware was published and downloaded nearly 1,500 times, posing risks to developers and users of this client-side security tool.
Hackers compromised the Injective Labs SDK GitHub repository to publish a malicious npm package that steals cryptocurrency wallet private keys and seed phrases. This malware poses a direct threat to developers and users managing crypto assets.
Microsoft has analyzed a new Windows backdoor called GigaWiper that merges three destructive tools: full disk wiping, Windows drive overwriting, and fake ransomware that scrambles files without saving keys. This modular malware gives operators multiple ways to disrupt or destroy infected machines.
A new EvilTokens campaign uses ghost phishing to bypass traditional email security by hiding malicious pages until decrypted inside a victim’s browser. This poses high risk to businesses using Microsoft 365 and handling sensitive data.
Threat actors are impersonating IT support via Microsoft Teams voice calls to trick employees into installing EtherRAT malware, compromising corporate networks. This tactic enables attackers to gain initial access and conduct further intrusion.