PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the ...
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Crooks are deploying cheeky browser-in-the-browser techniques to trick victims into downloading RMM tools.
Chrome zero-day CVE-2026-85046 is under active attack as the sixth actively exploited Chrome vulnerability of 2026. A type confusion flaw in Chrome's V8 JavaScript engine lets attackers run code ...
BlueMoon exploit kit, shared by four China-linked spy groups in 12 days, chains Chrome and Windows zero-days to hand ...
Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the ...
Once installed, it can turn Google Chrome or Microsoft Edge into a persistent backdoor for stealing browser data, hijacking ...
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension ...
A malicious installer disguised as the Exodus cryptocurrency wallet is being used to deploy a modular remote-access trojan ...
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote ...