Check Point's static deobfuscation exposes JSCeal, a compiled V8 malware family that replays stolen cookies into Google accounts.
North Korea-linked actors are using fake full-screen macOS updates to push ClickFix-style clipboard attacks.
A malvertising campaign called SourTrade makes victims' browsers download and assemble malicious executables using a legitimate runtime.