40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 malicious Mozilla Firefox extensions has been discovered masquerading as popular Web3 products like OKX, Rabby Wallet, and TronLink…
A set of 40 malicious Mozilla Firefox extensions has been discovered masquerading as popular Web3 products like OKX, Rabby Wallet, and TronLink…
RST Cloud documented a static API key across four confirmed C2 domains and identified additional candidates via recurring URI patterns, aiding in…
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, by correlating endpoint and network…
Cybersecurity researchers have uncovered a new Python-based implant framework called TWINLOOT that abuses trusted Microsoft services for command-and-control (C2) operations. The malware,…
Cybersecurity researchers have disclosed details of a factory-shipped backdoor implanted in at least 20 Chinese router models from Zbtlink. According to a…
A suspected Chinese-speaking threat actor has been conducting a series of cyber attacks against government organizations in Central Asia since January 2025.…
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN,…
PhantomEnigma is a modular backdoor built on Inno Setup and Node.js, hidden inside patched Electron applications like Boostnote. It collects system information,…