A steal-everything platform called Lunex disables endpoint defenses through a vulnerable AMD driver before it grabs browser and wallet data.
The documentation stand-in third-party[.]com has been weaponised, serving a ClickFix lure that poisons the clipboard on Windows machines.
Attackers used a long-lived Cloudflare API key stored in Brevo's own source code to push malware through the marketing platform's…
A verified HBO Max Reddit account pushed 108 malicious ads in 48 hours, part of a broader operation spreading infostealers.
A government-linked Indian IT portal served a fake Cloudflare check that tried to get visitors to run a copied command.
Symantec documents attackers abusing signed node.exe to run JavaScript payloads in intrusions since February.
CRPx0's white-label ransomware service claims 48 victims as ClickFix lures spread to Windows and macOS.
Microsoft tracks a ClickFix variant that drops a Python reverse tunnel through fake CAPTCHA overlays.