A spoofed CCleaner download site is spreading a multi-stage malware that hijacks Chrome to steal credentials, cookies, and authentication tokens while recording keystrokes and screenshots.
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
A legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion monthly downloads. The Wave Six payload hid inside AI agent config files ...
Three suspected Russian cyber-espionage clusters are abusing legitimate authentication features to compromise personal ...
A campaign with fake websites displays correct-looking links, but tricks victims into downloading unwanted software.
Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach.
On Thursday, Google’s Threat Intelligence Group (GTIG) said it's now tracking two other suspected Russian groups, UNC7005 and ...
BdThemes' compromised JSON feed exploits XSS in seven WordPress plugins, creating rogue admins and installing a PHP web shell without plugin updates.
A phishing campaign targeting cybersecurity conference attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own ...
Kaspersky researchers found 92,000 malicious attacks disguised as AI services in 2026, with fake ChatGPT, Claude and Gemini ...
Chrome security update 151.0.7922.169/.170 patches 15 vulnerabilities, including two Critical sandbox-escape buffer overflows ...