A verified HBO Max Reddit account pushed 108 malicious ads in 48 hours, part of a broader operation spreading infostealers.
Okta found thousands of live AI session tokens in a stealer log, letting thieves replay their way into paid tools.
Elastic finds four REVSTEALER companion modules that persist after the stealer deletes itself, including one that mines crypto.
A GitHub repo promising free Claude Opus 5 is quietly installing the RevStealer infostealer, according to Morphisec.
Anthropic locks victims out and refunds charges after infostealers hijack active login sessions.
Fake Minecraft client sites keep ranking at the top of search results while dropping the WeedHack infostealer.
Socket found 40 malicious Firefox extensions posing as Web3 products to drain recovery phrases and private keys.
A seller posting employee directories claims they came from Azure tenants of nine companies, and Hudson Rock says the samples…