A large-scale fake invitation phishing attack is actively targeting organizations across the United States, using convincingly … Phishing Campaign Uses Fake Invites to Steal CredentialsRead more
credential theft
TamperedChef Malware Hides Stealth Attacks Inside Signed Apps
One of the most aggressive supply chain attacks in recent memory has struck the developer ecosystem. … TamperedChef Malware Hides Stealth Attacks Inside Signed AppsRead more
Megalodon Attack Injects Backdoors Into 5,500+ GitHub Repositories
One of the most aggressive supply chain attacks in recent memory has struck the developer ecosystem. … Megalodon Attack Injects Backdoors Into 5,500+ GitHub RepositoriesRead more
Ukrainian Police Identify Teen Behind Global Infostealer Campaign
An 18-year-old hacker from Odessa has been identified by Ukrainian cyber police as the operator behind … Ukrainian Police Identify Teen Behind Global Infostealer CampaignRead more
Poisoned IDE Extensions: Lessons from the 2026 GitHub Supply Chain Attack
The modern developer workspace has become the frontline of enterprise cyber warfare. Integrated Development Environments (IDEs), … Poisoned IDE Extensions: Lessons from the 2026 GitHub Supply Chain AttackRead more
Warning: Fake Claude AI Installer Used to Spread Malware
A new cyber campaign is exploiting one of the fastest-growing trends in tech—AI adoption—to trick users … Warning: Fake Claude AI Installer Used to Spread MalwareRead more
Malicious NuGet Packages Compromise 64K+ Developer Systems
A stealthy supply chain attack is quietly spreading through the .NET ecosystem, targeting developers and build … Malicious NuGet Packages Compromise 64K+ Developer SystemsRead more
macOS ClickFix Malware: Fake Fixes Hiding Infostealers
Imagine searching online for a quick fix to a common macOS issue—like low disk space—and finding … macOS ClickFix Malware: Fake Fixes Hiding InfostealersRead more
Malicious “tanstack” Package Hijacks npm to Steal Dev Secrets
On April 29, 2026, a highly targeted supply chain attack hit the JavaScript ecosystem. An attacker … Malicious “tanstack” Package Hijacks npm to Steal Dev SecretsRead more
Warning: New Fake CAPTCHA Scam Explodes Credential Theft
Cybercriminals have found a psychological “cheat code” to bypass your security: the CAPTCHA. In the first … Warning: New Fake CAPTCHA Scam Explodes Credential TheftRead more