Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal ...
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency ...
Cloudflare Workers Spectre attack research published August 19, 2026 showed JWT token theft at 12 bits per second in live ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
GitHub Copilot's app now runs coding agents inside WSL, and Google confirms WSL and native Windows support are both coming to ...
Group-IB said its researchers had tracked the Outsider Phishing Kit, operated by a threat actor known as ChenLun, and ...
Malicious Chrome and Edge extensions stole crypto, credentials, sessions, and browser data in a campaign active since early ...
Magento zero-day vulnerability CVE-2026-75650 exploited a fully patched store for three days before Adobe released APSB26-146 on September 7. A self-updating Rust backdoor survived the patch, evaded ...
browser extensions were compromised, with malicious updates stealing crypto wallet secrets, passwords, and sensitive user ...