JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
BlueMoon chains Chrome and Windows zero-days to escape the browser sandbox, elevate privileges, and deliver malware on ...
BlueMoon exploit kit, shared by four China-linked spy groups in 12 days, chains Chrome and Windows zero-days to hand ...
Crooks are deploying cheeky browser-in-the-browser techniques to trick victims into downloading RMM tools.
Magento zero-day vulnerability CVE-2026-75650 exploited a fully patched store for three days before Adobe released APSB26-146 ...
AI agents helped attackers launch a cloud credential theft campaign in under six hours, stealing thousands of third-party ...
Thousands of hacked sites use fake CAPTCHA prompts to trick visitors into running malware. Learn the warning signs before ...
Recruiters lure developers with fake coding tests that deliver NodeRabbit and PollCat remote-access malware onto their ...
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote ...
Threat actors are beginning to test a new way to evade AI-powered security tools: placing harmful prompt-injection content ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results