New CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
Huntress researchers have uncovered a new ClickFix-style attack campaign targeting macOS users with a Go-based stealer malware capable of stealing cryptocurrency, browser…
Cybersecurity researchers at Arctic Wolf Labs have uncovered a widespread email-driven phishing campaign that uses adversary-in-the-middle (AitM) techniques to compromise Microsoft 365…
Storm-2657 is a threat actor tracked by Microsoft, associated with phishing campaigns targeting Microsoft 365 accounts. Documented since early 2025, it shares…
TeamPCP is a cybercrime group alleged to have compromised open-source projects like Trivy, Checkmarx KICS, and LiteLLM in March 2026. The group…
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and…
GitGuardian researchers have uncovered a significant security risk affecting n8n, a popular open-source workflow automation platform. By scanning public GitHub commits, they…
A cluster of 77 malicious extensions on the Open VSX marketplace has been discovered impersonating legitimate developer tools while exfiltrating sensitive information…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack targeting users of Alibaba developer tools with a cross-platform remote access trojan…