Suspected TraderTraitor actors abuse a trojanized Terraform provider to deploy cross-platform malware targeting credentials ...
China-linked threat actors combine automated tools with hands-on hacking techniques to steal sensitive data in targeted cyber ...
Compromised TensorLake npm SDK v0.5.144 deploys a credential-stealing worm targeting GitHub, AWS, Kubernetes, and AI ...
BlueMoon chains Chrome V8 flaws with a Windows kernel exploit to deploy GemStone, ShadowPad, and Rust-based malware in ...
ClickFix abuses browser cache smuggling, VBScript, PowerShell, and .NET payloads to bypass Windows Run limits and steal ...
NetScaler zero-days enable RCE, memory corruption, web shell deployment, log poisoning, and persistence on vulnerable ADC and Gateway systems ...
Attackers exploit Citrix NetScaler zero-days CVE-2026-88772 and CVE-2026-88771 to gain root access, deploy web shells, and ...
Threat actors abuse Action1 RMM via phishing PDFs, VBS, and MSI packages to establish persistence and unauthorized remote access ...
GlassWorm-linked VS Code extensions abuse theme packages, obfuscated JavaScript, AES-256-CBC, and Solana dead drops to ...
Threat actors are leveraging phishing campaigns to deliver a legitimate MSP360 RMM installer disguised as trusted software. Once launched, the installer establishes persistence and subsequently ...
Test and strengthen defenses against Dire Wolf ransomware by validating detection coverage, response readiness, and security ...