WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 ...
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
MCP server in Compose Hot Reload allows agents to trigger reloads, take screenshots, inspect the semantic tree, simulate text ...
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads ...
Chrome zero-day CVE-2026-85046 is under active attack as the sixth actively exploited Chrome vulnerability of 2026. A type confusion flaw in Chrome's V8 JavaScript engine lets attackers run code ...
A phishing campaign targeting cybersecurity conference attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own ...
Google has patched an actively exploited flaw in Chrome's V8 engine. Here's what Northeast Philadelphia users need to do ...
I thought Linux running inside a PDF sounded impossible, so I tried it myself—and ended up with a working Linux terminal in a ...
Fake Adobe Acrobat sites are hiding malware-as-a-service panels, using document lures to target Windows users with harmful ...
A malicious installer disguised as the Exodus cryptocurrency wallet is being used to deploy a modular remote-access trojan ...