-
Apple’s internal Biome framework is rapidly emerging as one of the most valuable sources of forensic intelligence on iOS, with newly analyzed data revealing detailed records of Safari browsing activity, Wallet transactions. Originally misunderstood due…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Claude Code has a flaw in its startup memory loader related to handling symbolic links (symlinks) that can unintentionally expose readable files from outside a cloned repository, without requiring explicit user approval. The issue arises not from the t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SparkKitty is a cross‑platform mobile stealer that weaponizes users’ photo galleries, using OCR to extract sensitive text from images and silently exfiltrating it to attacker‑controlled C2 servers on both Android and iOS. Built as an apparent successor…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project cre…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit. That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic’s Claude includes a share feature that creates a publicly accessible URL for conversations, allowing users to share AI chats with colleagues, clients, or friends. However, this convenience also brings exposure risks when shared URLs are poste…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical remote code execution (RCE) vulnerability chain in GitLab’s Jupyter Notebook diff renderer. This issue is rooted in two long-standing memory safety vulnerabilities within the Oj Ruby JSON parser. The vulnerabilities impact both GitLab Commun…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers have already unlocked the front door for them. D…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate inconsistencies between legacy tracking conventions used ac…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from vict…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


