CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every ...
ANY.RUN reveals how PhantomEnigma abused compromised Brazilian government infrastructure, uncovered a new backdoor generation ...
The parents of a three-month-old boy who they fear has just days to live say they're frustrated at being unable to access ...
A new macOS ClickFix campaign is tricking users into running malicious Terminal commands to deploy a persistent backdoor and ...
Attackers created at least 292 fake GitHub repositories that impersonated developer tools and redirected users to ...
Attackers were found using a Lua-based malware loader posing as a TrueType font tile, with layered obfuscation and fileless ...
A large-scale phishing operation has been observed disguising a malicious script as a TrueType font file (.tff). Using the ...
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This ...
JFrog finds 148 npm proxy packages turned student browsers into a DDoS botnet, while a mutable loader lets operators re-arm ...
By some benchmarks, Julia code can run 10X to 1,000X faster than Python—but there’s a reason it’s not a very popular ...
North Korean threat actors are escalating the PolinRider supply chain attack across Go, Packagist, and npm package environments. The threat cluster – identified as Contagious Interview or Famous ...
A SimpleHelp authentication flaw is being exploited to deploy Djinn Stealer, a cross-platform malware targeting cloud, developer, and AI credentials.