Researchers have uncovered a Blind Eagle-linked malware operation that uses GitHub repositories, phishing lures, VBScript, ...
Blind Eagle-linked hackers target Colombia with phishing emails, password-protected archives, and malware to evade detection ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
An information-stealing virus was uploaded to a GitHub repository disguised as downloadable weights for Alibaba's Qwen 3.8 ...
Newer versions of the Google Sites lure infrastructure also attempt to evade detection by serving benign content when visited ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
Cato Networks Ltd.’s Cato CTRL threat research team today detailed a macOS attack campaign built around a fake OpenAI Codex ...
AmnesiaStealer targets Macs via fake GitHub pages, stealing passwords, browser sessions, crypto data, and sensitive files.
A Huntress researcher was contacted by an X account with the handle "@HartmansDoeke," who claimed to be the vice president ...
Cybercriminals are using fake Claude installation guides to infect Mac users with MacSync, a sophisticated information ...
AmnesiaStealer macOS malware steals credentials and gives attackers live hidden control of Chromium browsers via DevTools.
As noted by MacRumors, the security firm Group-IB has identified a new piece of macOS malware in the wild that pressures users into surrendering their passwords via a barrage of fake system prompts.