Malware & Threats

Venom Stealer Raises Stakes With Continuous Credential Harvesting

Venom Stealer Raises Stakes With Continuous Credential Harvesting 2026-03-31 at 17:56 By Kevin Townsend Licensed malware with built-in persistence and automation enables attackers to continuously siphon credentials, session data, and cryptocurrency assets. The post Venom Stealer Raises Stakes With Continuous Credential Harvesting appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Venom Stealer Raises Stakes With Continuous Credential Harvesting Read More »

Telnyx Targeted in Growing TeamPCP Supply Chain Attack

Telnyx Targeted in Growing TeamPCP Supply Chain Attack 2026-03-30 at 14:26 By Ionut Arghire Two malicious versions of the popular SDK were uploaded to the PyPI registry, targeting Windows, macOS, and Linux. The post Telnyx Targeted in Growing TeamPCP Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Telnyx Targeted in Growing TeamPCP Supply Chain Attack Read More »

Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs 2026-03-28 at 15:40 By Ionut Arghire The infection chain includes a fake CAPTCHA page, a Bash script, a Nuitka loader, and the Python-based infostealer. The post Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs Read More »

Alleged RedLine Malware Administrator Extradited to US

Alleged RedLine Malware Administrator Extradited to US 2026-03-26 at 12:06 By Eduard Kovacs Hambardzum Minasyan of Armenia has been accused of being involved in the development and administration of the infostealer malware. The post Alleged RedLine Malware Administrator Extradited to US appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Alleged RedLine Malware Administrator Extradited to US Read More »

From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI

From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI 2026-03-25 at 14:00 By Ionut Arghire The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$. The post From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI appeared

From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI Read More »

Stryker Says Malicious File Found During Probe Into Iran-Linked Attack

Stryker Says Malicious File Found During Probe Into Iran-Linked Attack 2026-03-24 at 11:30 By Eduard Kovacs The FBI has published an alert describing the malware used by Iranian government hackers. The post Stryker Says Malicious File Found During Probe Into Iran-Linked Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Stryker Says Malicious File Found During Probe Into Iran-Linked Attack Read More »

Russian APT Exploits Zimbra Vulnerability Against Ukraine

Russian APT Exploits Zimbra Vulnerability Against Ukraine 2026-03-19 at 16:53 By Ionut Arghire Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser. The post Russian APT Exploits Zimbra Vulnerability Against Ukraine appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Russian APT Exploits Zimbra Vulnerability Against Ukraine Read More »

Iranian Hackers Likely Used Malware-Stolen Credentials in Stryker Breach

Iranian Hackers Likely Used Malware-Stolen Credentials in Stryker Breach 2026-03-18 at 14:49 By Eduard Kovacs The medtech giant has been working on restoring systems affected by the cyberattack conducted by the Handala hackers. The post Iranian Hackers Likely Used Malware-Stolen Credentials in Stryker Breach appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Iranian Hackers Likely Used Malware-Stolen Credentials in Stryker Breach Read More »

174 Vulnerabilities Targeted by RondoDox Botnet

174 Vulnerabilities Targeted by RondoDox Botnet 2026-03-17 at 14:47 By Ionut Arghire The botnet has increased its activity, peaking at 15,000 exploitation attempts per day, and taking a more targeted approach. The post 174 Vulnerabilities Targeted by RondoDox Botnet appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

174 Vulnerabilities Targeted by RondoDox Botnet Read More »

Threat Actor Targeting VPN Users in New Credential Theft Campaign

Threat Actor Targeting VPN Users in New Credential Theft Campaign 2026-03-16 at 14:28 By Ionut Arghire Storm-2561 is distributing fake VPN clients through SEO poisoning, deploying trojans, and stealing login information. The post Threat Actor Targeting VPN Users in New Credential Theft Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Threat Actor Targeting VPN Users in New Credential Theft Campaign Read More »

ForceMemo: Python Repositories Compromised in GlassWorm Aftermath

ForceMemo: Python Repositories Compromised in GlassWorm Aftermath 2026-03-16 at 13:51 By Ionut Arghire Hundreds of GitHub accounts were accessed using credentials stolen in the VS Code GlassWorm campaign. The post ForceMemo: Python Repositories Compromised in GlassWorm Aftermath appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

ForceMemo: Python Repositories Compromised in GlassWorm Aftermath Read More »

In Other News: N8n Flaw Exploited, Slopoly Malware, Interpol Cybercrime Crackdown

In Other News: N8n Flaw Exploited, Slopoly Malware, Interpol Cybercrime Crackdown 2026-03-13 at 16:29 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: Telus Digital data breach, vulnerabilities in Linux AppArmor allow root privileges, US defense contractor behind Coruna exploits. The post In Other News: N8n Flaw Exploited, Slopoly Malware, Interpol

In Other News: N8n Flaw Exploited, Slopoly Malware, Interpol Cybercrime Crackdown Read More »

Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet

Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet 2026-03-13 at 10:31 By Eduard Kovacs Law enforcement agencies in the US and Europe targeted the cybercrime service that has impacted 360,000 devices since 2020. The post Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet appeared first on SecurityWeek. This article is an excerpt from

Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet Read More »

Polyfill Supply Chain Attack Impacting 100k Sites Linked to North Korea

Polyfill Supply Chain Attack Impacting 100k Sites Linked to North Korea 2026-03-12 at 11:48 By Eduard Kovacs The 2024 incident was initially linked to China, but an infostealer infection has now revealed North Korean involvement. The post Polyfill Supply Chain Attack Impacting 100k Sites Linked to North Korea appeared first on SecurityWeek. This article is

Polyfill Supply Chain Attack Impacting 100k Sites Linked to North Korea Read More »

‘BlackSanta’ Malware Activates EDR and AV Killer Before Detonating Payload

‘BlackSanta’ Malware Activates EDR and AV Killer Before Detonating Payload 2026-03-11 at 11:42 By Kevin Townsend The malware disables antivirus and EDR protections at the kernel level, clearing the path for credential harvesting, system reconnaissance, and eventual data exfiltration. The post ‘BlackSanta’ Malware Activates EDR and AV Killer Before Detonating Payload appeared first on SecurityWeek.

‘BlackSanta’ Malware Activates EDR and AV Killer Before Detonating Payload Read More »

ClickFix Attack Uses Windows Terminal to Evade Detection

ClickFix Attack Uses Windows Terminal to Evade Detection 2026-03-09 at 15:37 By Ionut Arghire Fake CAPTCHA pages instruct victims to paste malicious commands in the Windows Terminal instead of the Run dialog. The post ClickFix Attack Uses Windows Terminal to Evade Detection appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

ClickFix Attack Uses Windows Terminal to Evade Detection Read More »

Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign

Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign 2026-03-09 at 13:50 By Ionut Arghire Threat actors replace legitimate commands on the cloned installation webpages with malicious commands. The post Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign Read More »

Over 100 GitHub Repositories Distributing BoryptGrab Stealer

Over 100 GitHub Repositories Distributing BoryptGrab Stealer 2026-03-07 at 14:46 By Ionut Arghire The malware targets browser and cryptocurrency wallet data, along with system information and user files. The post Over 100 GitHub Repositories Distributing BoryptGrab Stealer appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Over 100 GitHub Repositories Distributing BoryptGrab Stealer Read More »

How Pirated Software Turns Helpful Employees Into Malware Delivery Agents

How Pirated Software Turns Helpful Employees Into Malware Delivery Agents 2026-03-04 at 14:48 By Kevin Townsend Employees seeking free versions of paid software may unknowingly install malware-laced “cracked” apps that can steal credentials, deploy cryptominers, or open the door to ransomware. The post How Pirated Software Turns Helpful Employees Into Malware Delivery Agents appeared first

How Pirated Software Turns Helpful Employees Into Malware Delivery Agents Read More »

North Korean APT Targets Air-Gapped Systems in Recent Campaign

North Korean APT Targets Air-Gapped Systems in Recent Campaign 2026-03-02 at 13:47 By Ionut Arghire Using Windows shortcut files, the APT deployed a new implant, a loader, a propagation tool, and two backdoors. The post North Korean APT Targets Air-Gapped Systems in Recent Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

North Korean APT Targets Air-Gapped Systems in Recent Campaign Read More »

Scroll to Top