ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
Group-IB has identified a new macOS infostealer, ClickLock Stealer, that uses a coercive technique to force victims to enter their login password.…
Group-IB has identified a new macOS infostealer, ClickLock Stealer, that uses a coercive technique to force victims to enter their login password.…
Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…
Attackers are distributing a data-stealing trojan named ChocoPoC through fake proof-of-concept (PoC) exploit repositories on GitHub, specifically targeting vulnerability researchers. The malware,…
Microsoft has discovered a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for.…
KuinaExtractor is a new Rust-based information stealer that harvests web browser data, crypto wallets, and credentials for Roblox, Steam, and Discord. It…
Microsoft has removed 119 malicious extensions from the Edge Add-ons store that used steganography to hide malware in image and font files.…
The open-source JavaScript engine used in Google Chrome. Vulnerable to CVE-2026-11645.
Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a…
Chrome's app-bound encryption (ABE) protections are targeted by ChocoShell to steal browser session cookies and saved passwords.
Cybersecurity researchers have uncovered a coordinated malware campaign on the JetBrains Marketplace involving 15 malicious plugins that exfiltrate AI provider API keys.…