CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every ...
A large-scale phishing operation has been observed disguising a malicious script as a TrueType font file (.tff). Using the ...
Attackers were found using a Lua-based malware loader posing as a TrueType font tile, with layered obfuscation and fileless ...
JFrog finds 148 npm proxy packages turned student browsers into a DDoS botnet, while a mutable loader lets operators re-arm ...
A SimpleHelp authentication flaw is being exploited to deploy Djinn Stealer, a cross-platform malware targeting cloud, developer, and AI credentials.
Another edition of Security Boulevard's after-action breach roundup, tracking the most significant incidents, disclosures and ...
Vulnerabilities in remote monitoring and management (RMM) tools can give attackers a direct path into enterprise environments, often with the same trusted access that IT administrators rely on to ...
A new macOS ClickFix campaign is tricking users into running malicious Terminal commands to deploy a persistent backdoor and ...
North Korean threat actors are escalating the PolinRider supply chain attack across Go, Packagist, and npm package environments. The threat cluster – identified as Contagious Interview or Famous ...
Sophisticated Mini Shai-Hulud supply chain attack expands from npm to Go ecosystem. Consequently, a compromised npm developer account likely allowed the attackers to push trojanized versions of 23 ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results