Saturday, September 12, 2026
Follow on LinkedIn

Threats

Hackers Hide RevStealer Inside Fake Claude Opus 5 App to Steal Passwords and Crypto

Hackers are using a fake Claude Opus 5 desktop application to distribute RevStealer, a Windows malware built to take passwords, browser data and cryptocurrency wallet material. The campaign turns demand for AI tools into a trap, giving victims a...

Popular npm Package With 150K Weekly Downloads Compromised in Mini Shai-Hulud Supply-Chain Attack

A JavaScript development package has been caught in a supply-chain compromise that can run malicious code when installed. The incident affects a tool with about 150,000 weekly downloads, risking developer and automated build systems. Attackers published ten tainted releases on...

Hackers Use Malicious Website Themes to Steal Crypto Wallet Seeds From iPhones

Hackers are using booby-trapped website themes to turn visits from iPhone users into a route for spyware and cryptocurrency theft. The campaign hides harmful code inside themes used by Vietnamese movie and comic streaming websites, exposing visitors without warning. The...

Hackers Compromise Cisco Routers to Spy on Networks and Reach Critical Infrastructure

Fire Ant has moved beyond attacking individual systems and is now compromising network infrastructure that organizations trust to move traffic and manage access. The actor has turned Cisco IOS XR routers into platforms for surveillance, remote connectivity, and movement...

Hackers Hide ValleyRAT Backdoor Inside Adware Targeting Users in China and India

Hackers are using adware to deliver ValleyRAT, a Windows backdoor. The campaign primarily affects users in China and India, turning a program expected to display ads into a route for spying, theft, and further malware delivery. The installer changes its...

19 Chrome and Edge Extensions Caught Stealing Crypto Wallets and Passwords

Nineteen browser extensions have been linked to a malware operation that steals cryptocurrency wallet secrets, passwords and other data. The extensions appeared to offer useful tools, including search helpers, price monitors and copy-unlocking features, before later updates quietly introduced...

Popular npm Package With 150K+ Weekly Downloads Hit by Credential-Stealing Supply-Chain Worm

A widely used npm package has become a credential-stealing delivery channel after attackers planted a self-spreading Shai-Hulud payload in its releases. The affected @7nohe/openapi-react-query-codegen package, which generates TanStack Query code, receives more than 150,000 weekly downloads. The malicious releases can run while...

Hackers Use Ethereum Blockchain to Steal Credit Card Data From Online Shoppers

Online shoppers can have their card details stolen without ever leaving a legitimate store. A tracked Magecart campaign plants malicious checkout code on compromised e-commerce sites, then uses Ethereum blockchain infrastructure to keep its delivery system active. The campaign, dubbed...

New AI-Built Malware Watches How Security Teams Remove It and Fights Back

A new Windows malware toolkit is showing how artificial intelligence can change the economics of cybercrime. Known as Gryxa, it gives a criminal operator remote access, stays active after partial cleanup, and targets passwords stored in Chromium-based browsers. It...

Hackers Use Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks

Hackers are using a fake Cloudflare CAPTCHA to turn a routine web check into a doorway into corporate networks. The campaign, called TerminalFix, begins on compromised websites and persuades visitors to paste a supposed verification command into Windows Terminal...

Latest News

Latest News