Threat actors compromised captive Wi-Fi gateways at hotels to silently redirect business travelers to fake Microsoft 365 login pages.
BlackFog researchers dissect MedusaHVNC, a remote access trojan that exploits Windows hidden desktops to hijack browser sessions and evade detection.
A new infostealer called ClickLock holds macOS desktops hostage by repeatedly killing applications until the user types their login password.
Attackers hijacked over 400 abandoned Arch Linux AUR packages by modifying build scripts to deploy a Rust credential stealer and…
Microsoft tracked 8.3 billion email-based phishing threats in Q1 2026 as CAPTCHA-gated attacks more than doubled in March, hitting 11.9…
Attackers exploited Google's legitimate no-code AppSheet platform to create and host fake login pages, evading traditional security filters and stealing…
Attackers are exploiting automated CI build processes by embedding credential-harvesting code into fake updates of widely-used open source packages.
The compromise cascaded from PyPI to npm to Packagist when a transitive dependency of pyannote-audio introduced the malicious Lightning package…
Sign in to your account