ThreatsDay: Malicious VS Code themes, npm supply-chain attacks, AI phishing, ransomware betrayal, exposed hacker tools, and ...
JPCERT/CC links Japan's recent data leaks to mobile API abuse and known software flaws, including an exploited Metabase SQL ...
MonsterCloud's owner is accused of charging ransomware victims over $19 million while secretly paying attackers over $8 ...
Sixteen malicious Firefox extensions imitate Rabby and OKX wallets to intercept recovery phrases and private keys during ...
Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised ...
Attackers used ARTEX and LLMs against South Korean financial organizations in a campaign that resulted in data exfiltration.
Wazza filters visitors with session tokens and browser checks before serving Adobe-themed Device Code phishing pages.
TrendAI links UAC-0099 to ASHVEIN, a .NET stealer and RAT used in attacks targeting Ukrainian government personnel.
The U.S. offers up to $10 million for information that identifies or locates Zhang Yu, charged over the HAFNIUM Exchange hacks.
Eight malicious npm packages downloaded 40,767 times deliver Overlord RAT, a Node.js stealer, and a downloader to Windows ...
LMCache CVE-2026-105192 lets unauthenticated attackers run code when the multiprocess server is bound to a routable address; no fix exists.
FBI and USSS warn FortiBleed remains active, using stolen credentials and traffic sniffing to harvest Fortinet authentication data.