-
International law enforcement agencies have successfully seized 106 servers and 101 domains as part of a coordinated global effort against the SocGholish malware infrastructure, marking a major milestone in Operation Endgame. Announced on June 18, 2026…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
International law enforcement dismantled TA569’s SocGholish infrastructure, taking down over 100 C2 servers and remediating nearly 15,000 compromised websites.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
DragonForce ransomware abused Microsoft Teams relay systems to hide a custom backdoor, steal files and encrypt systems at a US services firm.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated social‑engineering campaign is leveraging AI‑generated YouTube narrators, ghost accounts across multiple platforms, and manipulated reputation signals to distribute a Rust‑based clipboard hijacker that steals cryptocurrency by replacing…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Socket says the extensions worked as wallpaper tools, but also logged user data, disguised install traffic as Google clicks, and fed ad sites.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Socket says the extensions worked as wallpaper tools, but also logged user data, disguised install traffic as Google clicks, and fed ad sites.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Sapphire Sleet’s latest macOS campaign uses crafted .scpt AppleScript lures that pipe curl output directly to osascript, enabling a compact, multi-stage payload chain that executes entirely within Script Editor and evades many built‑in macOS protection…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are using 15 malicious JetBrains plugins posing as AI coding assistants to steal DeepSeek, OpenAI, and other developer API keys.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated malware campaign has been abusing Steam Workshop’s sharing model to distribute backdoors, infostealers and crypto miners hidden inside Wallpaper Engine packages, primarily targeting gamers in China and Russia. The campaign exploits Wall…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Rokarolla, a new Android banking trojan named after its Command-and-Control (C2) infrastructure, that combines sophisticated social engineering, broad permissions abuse, and a flexible command set to harvest credentials from 217 targeted banking and cr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


