A verified HBO Max Reddit account pushed 108 malicious ads in 48 hours, part of a broader operation spreading infostealers.
A recently patched Chrome and Windows exploit chain is now delivering two separate espionage toolsets against NGO targets.
A government-linked Indian IT portal served a fake Cloudflare check that tried to get visitors to run a copied command.
Okta found thousands of live AI session tokens in a stealer log, letting thieves replay their way into paid tools.
SOCRadar details PEEP, a post-compromise toolkit that rides a fake bookmarks extension from the browser out to host-level command execution.
Group-IB details BraZetsu, a Python malware framework that stocks a paid marketplace with hacked Windows hosts.
Symantec documents attackers abusing signed node.exe to run JavaScript payloads in intrusions since February.
A Russian man is extradited to face charges over Excel macro malware sent to roughly 80,000 freelancers.