Hackers are using a fake Claude Opus 5 desktop application to distribute RevStealer, a Windows malware built to take passwords, browser data and cryptocurrency wallet material.
The campaign turns demand for AI tools into a trap, giving victims a...
A JavaScript development package has been caught in a supply-chain compromise that can run malicious code when installed. The incident affects a tool with about 150,000 weekly downloads, risking developer and automated build systems.
Attackers published ten tainted releases on...
Hackers are using booby-trapped website themes to turn visits from iPhone users into a route for spyware and cryptocurrency theft.
The campaign hides harmful code inside themes used by Vietnamese movie and comic streaming websites, exposing visitors without warning.
The...
Fire Ant has moved beyond attacking individual systems and is now compromising network infrastructure that organizations trust to move traffic and manage access.
The actor has turned Cisco IOS XR routers into platforms for surveillance, remote connectivity, and movement...
Hackers are using adware to deliver ValleyRAT, a Windows backdoor. The campaign primarily affects users in China and India, turning a program expected to display ads into a route for spying, theft, and further malware delivery.
The installer changes its...
Nineteen browser extensions have been linked to a malware operation that steals cryptocurrency wallet secrets, passwords and other data.
The extensions appeared to offer useful tools, including search helpers, price monitors and copy-unlocking features, before later updates quietly introduced...
A widely used npm package has become a credential-stealing delivery channel after attackers planted a self-spreading Shai-Hulud payload in its releases.
The affected @7nohe/openapi-react-query-codegen package, which generates TanStack Query code, receives more than 150,000 weekly downloads.
The malicious releases can run while...
Online shoppers can have their card details stolen without ever leaving a legitimate store. A tracked Magecart campaign plants malicious checkout code on compromised e-commerce sites, then uses Ethereum blockchain infrastructure to keep its delivery system active.
The campaign, dubbed...
A new Windows malware toolkit is showing how artificial intelligence can change the economics of cybercrime.
Known as Gryxa, it gives a criminal operator remote access, stays active after partial cleanup, and targets passwords stored in Chromium-based browsers. It...
Hackers are using a fake Cloudflare CAPTCHA to turn a routine web check into a doorway into corporate networks.
The campaign, called TerminalFix, begins on compromised websites and persuades visitors to paste a supposed verification command into Windows Terminal...