ThreatsDay: Malicious VS Code themes, npm supply-chain attacks, AI phishing, ransomware betrayal, exposed hacker tools, and ...
JPCERT/CC links Japan's recent data leaks to mobile API abuse and known software flaws, including an exploited Metabase SQL ...
MonsterCloud's owner is accused of charging ransomware victims over $19 million while secretly paying attackers over $8 ...
Sixteen malicious Firefox extensions imitate Rabby and OKX wallets to intercept recovery phrases and private keys during ...
Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised ...
Attackers used ARTEX and LLMs against South Korean financial organizations in a campaign that resulted in data exfiltration.
Wazza filters visitors with session tokens and browser checks before serving Adobe-themed Device Code phishing pages.
TrendAI links UAC-0099 to ASHVEIN, a .NET stealer and RAT used in attacks targeting Ukrainian government personnel.
The U.S. offers up to $10 million for information that identifies or locates Zhang Yu, charged over the HAFNIUM Exchange hacks.
Eight malicious npm packages downloaded 40,767 times deliver Overlord RAT, a Node.js stealer, and a downloader to Windows ...
LMCache CVE-2026-105192 lets unauthenticated attackers run code when the multiprocess server is bound to a routable address; no fix exists.
FBI and USSS warn FortiBleed remains active, using stolen credentials and traffic sniffing to harvest Fortinet authentication data.
Results that may be inaccessible to you are currently showing.
Hide inaccessible results