-
SharkLoader, used by an intrusion cluster tracked as StrikeShark to deliver Cobalt Strike Beacon entirely in memory across a wide international footprint. The campaign combines opportunistic exploitation of exposed internet-facing infrastructure with c…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry pa…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A novel, practical ransomware technique that runs entirely inside the browser by abusing the File System Access API, demonstrating how AI can turn high-level malicious ideas into operational attack chains without any native payload. The proof-of-concep…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware-proof backup planning helps IT teams protect clean data copies, isolate storage, test recovery, and keep operations running after cyber attacks fast.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
McAfee says a Google Notes browser extension is replacing copied crypto payment details, putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake Interpol investigation emails are targeting small businesses with Proton Drive links that deliver ransomware, encrypt files, and route victims to Tox chat.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
MacSync Stealer is a newly discovered macOS infostealer actively distributed through a sophisticated malvertising campaign on Google Ads that impersonates Anthropic’s Claude Code CLI. Security researchers from Beezlebub have uncovered the complete atta…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An emergent supply-chain attack vector they term “phantom squatting,” in which large language models (LLMs) routinely hallucinate plausible but nonexistent domains for legitimate brands and adversaries then preemptively register those domai…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A fake FIFA World Cup 2026 T-shirt giveaway scam is spreading Voidrift malware through personalized emails using company logos and trusted websites to bypass security filters.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


