A new threat is combining GitHub resources and Telegram bots to infect devices and install backdoor malware. Researchers from Netskope recently found a new backdoor malware in the wild. While the malware is...
A 2022 piece of macOS malware is back. XCSSET is an advanced modular Mac environment-targeting malware. The new version has been updated to steal funds from digital wallets, collect data from the Notes...
The takeover and use of WordPress sites to distribute malware or to phish for data are not unusual cybercriminal techniques. Most users trust WordPress sites to be safe, and a lot of sites...
DeepSeek, a Chinese AI startup, is the latest big thing in the hype surrounding AI. Low prices on its paid models and open-source versions, in addition to the controversy of Chinese AI competing...
A new large-scale cybercriminal operation has been identified operating in the wild. This new threat campaign ran over 1,000 fake sites, impersonating WeTransfer and Reddit. The goal of the campaign is to trick...
United States Postal Service (USPS) scams, which have been around for decades, are experiencing a comeback. The classic “you’ve got a package to be delivered” scam is being updated with new techniques to...
A new campaign exclusively targeting macOS developers was spotted in the wild. The threat leverages a popular attack chain that includes malvertising, abuse of the Google Ads platform, fake phishing sites, and download...
Banshee, a stealer that emerged in mid-2024 to target macOS users, has received an alarming update. The developers behind Banshee have “stolen” Apple’s XProtect encryption, giving the malware increased stealth and attack rate...
A battle to dominate the world of crypto wallet drainers has been unfolding on the dark web. Throughout 2024, a handful of cyber criminal gangs that offer crypto drainers and phishing-as-a-service have proliferated....
The Realst Mac-targeting infostealer is back. This time, the Rust-written crypto-data stealer has been deployed in what looks like a laser-focused spear phishing campaign in which a threat actor is going after Web3...