-
GoDaddy researchers found WordPress malware using Steam Community profile comments to hide encoded command and control data, with nearly 1,980 sites affected.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Consider the history of any recent corporate scandal, and it is quite possible to guess what the story…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
pretalx XSS flaw lets attackers hijack conference organizer accounts, steal sessions, auto-accept talks, and demote admins. Patched in v2026.1.0.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are using fake purchase order emails and process hollowing to deploy fileless PureLogs malware to steal Windows users’ browser, crypto, and Discord data.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake Anthropic websites are being used to target Claude Code users with a fileless infostealer campaign that steals browser credentials and evades detection.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Iran’s Nimbus Manticore hackers used trojanized Zoom installers to deploy malware against US firms during a wider IRGC linked cyber campaign.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


