A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals ...
A Russian state-linked hacking group has been quietly raiding email accounts at NATO government agencies, defense contractors, and critical infrastructure operators since mid-2025 using a zero-click ...
A macOS ClickFix campaign uses more than 250 domains and server-side fingerprinting to hide AMOS lures from crawlers and ...
The IT team that reset passwords and wiped the infected machine may not have solved the problem. On July 29, cybersecurity firm Proofpoint disclosed a previously unknown browser-based implant called ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job ...
A Zimbra phishing campaign attributed to Russian state-supported cyber actors has targeted Western government and commercial organizations, exploiting CVE-2025-66376 to access sensitive email data and ...