-
Proofpoint says TA4922, a suspected China aligned cybercrime group, is targeting UK and European organisations with tax, payroll and benefits themed malware campaigns.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake ChatGPT desktop app ads pushed password-stealing malware by abusing trusted AI links, hiding from scanners, and tricking users into downloads.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GoDaddy researchers found WordPress malware using Steam Community profile comments to hide encoded command and control data, with nearly 1,980 sites affected.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Consider the history of any recent corporate scandal, and it is quite possible to guess what the story…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
pretalx XSS flaw lets attackers hijack conference organizer accounts, steal sessions, auto-accept talks, and demote admins. Patched in v2026.1.0.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are using fake purchase order emails and process hollowing to deploy fileless PureLogs malware to steal Windows users’ browser, crypto, and Discord data.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake Anthropic websites are being used to target Claude Code users with a fileless infostealer campaign that steals browser credentials and evades detection.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


