Monday, September 14, 2026
Follow on LinkedIn

Threats

Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users

A browser extension promoted as a Twitch viewing helper has been found sending live account tokens through servers controlled by its operator. The add-on, called “Twitch Enhanced Viewer | JeetBot,” was available to Chrome and Firefox users and advertised...

Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning

Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall Management Center devices, where it can maintain remote access, inspect traffic, and map systems behind...

One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users

A single click on a malicious link could have given attackers a direct path into Windows systems running Sogou Input Method. The flaw turned a commonly installed Chinese-language typing tool into an entry point for the GRAYRABBIT backdoor, exposing...

Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites

Casbaneiro is targeting online banking users in Latin America through phishing messages that look like urgent invoices or legal notices. The campaign uses personalised PDF lures to push recipients toward a malicious download chain, putting email data, banking activity...

Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker

Hackers are turning ordinary searches and gaming videos into malware traps. A long-running campaign used YouTube channels and search-engine manipulation to steer victims toward installers that looked like useful software, game tools or performance fixes. The activity is tied to...

Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process

Hackers are using a familiar Windows automation tool to hide AsyncRAT, a remote-access trojan, inside a trusted system process. The campaign starts with a deceptive batch file named “Right-click to open Invoice Details.bat,” which can appear harmless to someone...

Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis

Russia-aligned operators are testing a new way to make artificial intelligence overlook malicious code. The technique, called GuardBreaker, hides a safety-sensitive request inside an otherwise ordinary script comment, hoping that an AI code scanner refuses to continue its work. The...

New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks

KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used repeated Telnet password guesses against a honeypot, then downloaded an ARM payload. It...

Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments

A large email fraud campaign used fake CEO messages and invoices to push employees toward payments of nearly $50,000. The operation did not rely on a malicious attachment or software flaw. Instead, it used ordinary email to deliver a...

New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims

A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links. Called Mantax Otax, the malware can lock files, watch the screen, intercept verification codes and secretly use a phone’s...

Latest News

Latest News