Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed ...
Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access ...
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
SynkLoader malware is spreading through Microsoft Teams phishing, using a fake Windows lock screen to steal credentials and enable remote access.
A new Microsoft Teams phishing campaign delivers SynkLoader malware capable of stealing passwords, tunneling traffic, and ...
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal ...
Cursor opens your repo, the repo opens you, If you want the good model I’m going to need to see your ID, Flock’s a Flocking ...
A weekly look at exploited flaws, exposed systems, supply-chain attacks, browser abuse, malware campaigns, and the security risks that mattered most.
LiteLLM supply chain attack exposed stolen credentials at 2,488 corporate firms in March 2026; security researcher Kevin ...
AI CEO testimony Congress: Twenty-nine House Democrats demanded Speaker Johnson compel OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei testify under oath on AI agent breaches hitting five ...