DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake…
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake…
ACR Stealer, an infostealer active since 2024, is targeting enterprise networks by stealing saved browser passwords, live session tokens, PDFs, Microsoft 365…
G-Core Labs is a cloud and edge services provider that hosted the IP address 92.38.177.17 used by the npm campaign infrastructure.
Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…
Attackers are distributing a data-stealing trojan named ChocoPoC through fake proof-of-concept (PoC) exploit repositories on GitHub, specifically targeting vulnerability researchers. The malware,…
Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a…
Microsoft Edge is a browser targeted by the information stealer in the DPRK malvertising campaign. The malware harvests data from Edge among…
Microsoft is the developer of the Edge browser and Sysmon. Sysmon Event IDs 8 and 10 can be used to detect process…