SecurityTicks

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets 2026-08-08 at 04:49 By ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the […]

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets Read More »

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data 2026-08-08 at 04:49 By A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data Read More »

Donald Trump’s media company to terminate Crypto.com deal

Donald Trump’s media company to terminate Crypto.com deal 2026-08-08 at 00:39 By Cointelegraph by Turner Wright The president’s company will unwind an agreement with Crypto.com to create a multibillion-dollar CRO treasury and reportedly not integrate prediction markets onto Truth Social. This article is an excerpt from Cointelegraph.com News View Original Source

Donald Trump’s media company to terminate Crypto.com deal Read More »

US Treasury’s OFAC sanctions 2 Iran-linked crypto exchanges

US Treasury’s OFAC sanctions 2 Iran-linked crypto exchanges 2026-08-07 at 23:02 By Cointelegraph by Turner Wright The US government sanctioned an individual and two crypto exchanges it said facilitated money laundering for a combined $5 million in digital assets linked to Iran. This article is an excerpt from Cointelegraph.com News View Original Source

US Treasury’s OFAC sanctions 2 Iran-linked crypto exchanges Read More »

Yahoo News’ AI-powered tool drew just 3% of its articles from conservative outlets: study

Yahoo News’ AI-powered tool drew just 3% of its articles from conservative outlets: study 2026-08-07 at 22:46 By Thomas Barrabi Media Research Center – a conservative watchdog that has previously called out Apple News, Google and other aggregators for alleged bias – conducted a review of the “Yahoo 100” feed. The tool “uses AI to

Yahoo News’ AI-powered tool drew just 3% of its articles from conservative outlets: study Read More »

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer 2026-08-07 at 21:48 By A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. “These packages appear to use AI slop squatted, or randomly

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer Read More »

This new ‘AI’ chatbot is actually just one very tired guy

This new ‘AI’ chatbot is actually just one very tired guy 2026-08-07 at 21:43 By Bianca Zalben The tongue-in-cheek project is advertised on a $6,000 San Francisco billboard, and was launched as a commentary on society’s increasingly automatic reliance on artificial intelligence. This article is an excerpt from Latest Technology News | New York Post

This new ‘AI’ chatbot is actually just one very tired guy Read More »

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street 2026-08-07 at 17:26 By SecurityWeek News Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Read More »

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect 2026-08-07 at 16:10 By King Orande and Cris Tomboc The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign leveraging a new social engineering method to deploy unauthorized ConnectWise ScreenConnect clients. Rather than relying on conventional phishing pages, the campaign recreates convincing software

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect Read More »

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP 2026-08-07 at 15:56 By WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP Read More »

200 accounts compromised in Swiss government’s Microsoft SharePoint breach

200 accounts compromised in Swiss government’s Microsoft SharePoint breach 2026-08-07 at 15:29 By Sinisa Markovic Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers.

200 accounts compromised in Swiss government’s Microsoft SharePoint breach Read More »

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers 2026-08-07 at 14:10 By A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers Read More »

Vishing Extortion Group UNC6671 Rebrands After Making Millions

Vishing Extortion Group UNC6671 Rebrands After Making Millions 2026-08-07 at 14:06 By Ionut Arghire Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Vishing Extortion Group UNC6671 Rebrands After Making Millions Read More »

Tish James, Kathy Hochul’s pursuit of Kalshi raises questions about why they’re ignoring Polymarket

Tish James, Kathy Hochul’s pursuit of Kalshi raises questions about why they’re ignoring Polymarket 2026-08-07 at 14:00 By Charles Gasparino Kalshi argues the suit is a death blow to its business. This article is an excerpt from Latest Technology News | New York Post View Original Source

Tish James, Kathy Hochul’s pursuit of Kalshi raises questions about why they’re ignoring Polymarket Read More »

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors 2026-08-07 at 13:58 By Mihir Bagwe Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors Read More »

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix 2026-08-07 at 13:00 By Eduard Kovacs NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek. This article is an excerpt

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix Read More »

I tested the new Samsung Galaxy Watch9: The health tracker’s most exciting features

I tested the new Samsung Galaxy Watch9: The health tracker’s most exciting features 2026-08-07 at 12:59 By Carly Stern The new watch, on sale today, tracks fitness and sleep, measures antioxidants in the skin, and an even do a body composition scan. This article is an excerpt from Latest Technology News | New York Post

I tested the new Samsung Galaxy Watch9: The health tracker’s most exciting features Read More »

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 2026-08-07 at 12:32 By Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables Read More »

Scroll to Top