Threat Intelligence — Page 4

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines
Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

EU, UK and France Sanction Russia Over Coordinated Hacking and Sabotage Campaign Across Europe
France summoned Russia's ambassador on Monday after European governments accused the FSB, Russia's main intelligence service, of running a campaign to spy on and disrupt critical infrastructure across more than a dozen countries.

Spanish police dismantle €140 million fraud ring that drained company bank accounts
Four arrests across Spain, Portugal and Panama close down a laundering network that pushed nearly €100 million through 800 bank accounts, much of it stolen through fake CEO emails.

Fake GitHub Pages Impersonate 292 Real Brands to Push Password-Stealing Malware
A Russian-speaking crew built hundreds of lookalike project pages for security tools, wallets and dev software. One click on 'Download Secure Content' handed over browser passwords, crypto wallets and chat sessions.

Ransomware Gang Claims Bosch and Synopsys Hacks. Synopsys Says It Sees Nothing.
A criminal group called D1R says it stole sensitive data from two major companies and will publish it unless it gets paid. One of those companies is pushing back.

LabubaRAT: New Rust Malware Poses as NVIDIA Software to Sneak Onto Windows PCs
Researchers at Blackpoint Cyber say the newly named tool gives attackers a quiet, reusable way back into infected machines.

ClickFix: The Fake Error Pop-Up That Tricks You Into Hacking Yourself
A scam that launched in 2024 has grown into a thriving criminal marketplace. Researchers say standard antivirus tools are missing it almost entirely, and they have built a new detection method to fill the gap.

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon
Researchers at JFrog say 148 malicious packages used the npm registry as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into a two-week attack campaign in May.

Fake Guardian Articles Are Tricking People Into Scam Investment Sites
Criminals are building convincing copies of trusted news websites, complete with fake celebrity stories, to push victims toward fraudulent trading platforms.

Scammers Are Calling Telstra Customers and Pretending to Help After Last Week's Outage
Criminals are cold-calling Australians and posing as Telstra staff in the days after a national network failure. Here is what happened, what data could be at risk, and what you should do if your phone rings.

Russian Spies Are Breaking Into the World's Routers. The Password Is Often Still 'Admin'.
A joint advisory from the US, UK, and a dozen allied nations warns that Russian FSB hackers have spent years walking into critical infrastructure networks through the digital equivalent of an unlocked front door.

Malicious Jscrambler npm package stole developer secrets for two hours before takedown
A poisoned release of the Jscrambler npm package was downloaded almost 1,500 times, scooping up cloud keys, wallet seed phrases and browser credentials before the company pulled it.

CrashStealer: the new Mac malware that slips past Apple's own safety checks
Researchers at Jamf Threat Labs say the C++-based stealer used an Apple-notarised installer to bypass Gatekeeper and grab passwords, browser data and crypto wallets from macOS users.

Chrome and Edge Yank ModHeader Extension After Hidden History Collector Found
The browser add-on had 1.6 million users. A dormant tracker sat inside its official store version, though no evidence suggests it ever ran.

Russia's FSB Is Quietly Hijacking Old Routers Across Critical Infrastructure, Allies Warn
A rare joint advisory from thirteen agencies details how FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, have spent over a decade pulling configs from misconfigured network gear.