Friday, August 28, 2026
Follow on LinkedIn

Malware

macOS Malware Leverages Google Ads and Legitimate Claude.ai Shared Chats to Deliver Malware

Threat actors are executing a sophisticated malvertising campaign targeting macOS users via poisoned Google Ads and deceptive artificial intelligence applications. Researchers recently uncovered an operation that redirects victims to fraudulent landing pages via sponsored search results. By combining trusted hosting platforms...

TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules

A highly sophisticated Brazilian banking trojan named TCLBANKER, tracked under the campaign REF3076, this malware represents a major update to the older Maverick and SORVEPOTEL families. It stands out because it uses a fake, signed Logitech installer to infect systems...

Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes

Researchers from the Czech Technical University in Prague have developed a new adversarial malware generator targeting Linux ELF binaries. It achieves a 67.74% evasion rate against ML-based malware detectors while keeping the payload fully functional. Published on arXiv on April 24,...

Hackers Compromised ILSpy WordPress Domain to Deliver Malware

A new supply chain attack targeting developers after threat actors compromised the official WordPress domain for ILSpy on April 6, 2026. Instead of providing the legitimate software, the hijacked website began redirecting visitors to a malicious webpage to deliver...

Hackers Weaponize Claude Code Leak to Spread Vidar and GhostSocks Malware

The cybersecurity community is on high alert following a massive source code leak from Anthropic. On March 31, 2026, the company accidentally exposed the complete source code for Claude Code, its flagship terminal-based coding assistant. The leak occurred due...

GlassWorm Campaign Uses 72 Malicious Open VSX Extensions to Broaden Reach

In a major escalation of supply chain attacks, the GlassWorm malware campaign has evolved to infect developer environments using transitive dependencies. On March 13, 2026, the Socket Research Team reported identifying at least 72 new malicious Open VSX extensions...

Authorities Dismantle Malicious Proxy Service Used to Deploy Malware Attacking Thousands of Users

An international law enforcement operation led by the U.S. Justice Department has successfully dismantled SocksEscort, a massive residential proxy network. The malicious service compromised thousands of home and small business routers worldwide, enabling cybercriminals to mask their identities while executing...

New Clickfix Exploit Tricks Users into Changing DNS Settings for Malware Installation

A new evolution in the ClickFix social engineering campaign, which now employs a custom DNS hijacking technique to deliver malware. This attack method tricks users into executing malicious commands that utilize DNS lookups to fetch the next stage of...

Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users

A sophisticated malware campaign targeting macOS users through Google-sponsored search results and legitimate platforms, including Anthropic's Claude AI and Medium. The campaign has already reached over 15,000 potential victims through two distinct attack variants that exploit users' trust in...

Promptware – Hackers Can Use Google Calendar Invites to Stream Victims’ Cameras via Zoom

A new and dangerous class of cyberattack called "Promptware" has been discovered, capable of turning your personal AI assistant into a sleeper agent that spies on you. Security researchers from Ben-Gurion University, Tel Aviv University, and Harvard have demonstrated a...

Latest News

Latest News