MacSync targets macOS crypto users with fake apps that steal passwords, wallet data and developer credentials.
A phishing campaign targeting recipients with Japanese- and Korean-language emails used fake damaged-product complaints to ...
Instinct saved me $550, booked my restaurant reservations, and warned me about a phishing scam. It also wasted $64 and might ...
Discover how AvisLoader uses Tox peer-to-peer messaging for C2, ClickFix delivery, shortcut persistence, and payload ...
Malicious Terraform providers and Go modules deliver Graphalgo-linked Go malware using blockchain and Slack for command and ...
JSAUX Steam Machine displays add custom screens to your setup. The E-Ink option offers a 22-day battery, while the Pixel ...
GHAPPIER supply-chain attack compromised 22 accounts, infecting 65 GitHub repositories and 73 files with a malicious npm loader.
Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
A malware campaign tracked as Rapuncel is abusing a Microsoft-attested kernel driver to disable endpoint protections before stealing credentials, cryptocurrency wallet data, messaging tokens, and ...