Researchers built a zero-click worm, dubbed WeWorm, that takes over WeChat accounts through incoming calls before Tencent's August fix.
Three August lures ended in rogue ScreenConnect clients that spread a four-stage VBScript chain to every new host.
The Mini Shai-Hulud worm uses a Bun runtime bootstrap to silently harvest credentials from developer machines, cloud platforms, and AI…