Tag: malicious
-
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials/
-
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365…
-
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures.The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed First seen…
-
IonStack Exploit Chain Lets Hackers Root Android 17 Phones With a Single URL Click
Nebula Security has revealed a significant exploit chain known as “IonStack,” demonstrating how attackers could gain full root access on Android 17 devices with just a single click on a malicious URL. This raises serious concerns about browser-to-kernel attack surfaces in today’s mobile ecosystems. The disclosure highlights a complex, multi-stage exploitation technique that combines two…
-
New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
Cyber threat actors are infecting victims with the Vidar stealer and the XMRig cryptocurrency miner in a new malicious campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-campaign-vidar-stealer-monero/
-
OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear
Scammers are hijacking government websites to upload ads for “leaked” OnlyFans content. Thousands of copyright complaints from adult creators are helping people avoid malicious links. First seen on wired.com Jump to article: www.wired.com/story/onlyfans-creators-dmca-hacked-government-websites/
-
Thousands of malicious AI skills found capable of stealing data, running malware
AI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/eset-ai-threat-trends-report/
-
AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another feature”‘packed botnet sales pitch: cross”‘platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capability”‘aware. AI compute…
-
Malicious websites trick AI agents into crypto payments, context poisoning
First seen on scworld.com Jump to article: www.scworld.com/news/malicious-websites-trick-ai-agents-into-crypto-payments-context-poisoning
-
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC.”The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the…
-
Fake Interview Phishing Campaign Impersonates Top Brands to Steal Gmail Credentials
A sophisticated interview-themed phishing campaign that impersonates major global brands to harvest Gmail credentials. Attackers pose as recruiters offering marketing roles at well-known companies, leveraging personalized targeting and a layered redirection chain that uses legitimate platforms to mask malicious intent. The result is a convincing lure that directs recipients to a Gmail credential prompt embedded…
-
Hidden Web Prompts Trick AI Agents Into Sending Money
Hidden prompts on malicious websites trick AI agents into making payments or trusting fake sites, exposing new risks for autonomous AI workflows. Zscaler ThreatLabz documented two active campaigns that embed hidden instructions in web pages to manipulate AI agents, not human users, though those get caught too. The technique is called indirect prompt injection: malicious…
-
Critical Opera GX Vulnerability Lets Attackers Inject CSS Across Every Webpage
A critical security vulnerability in Opera GX has been disclosed, revealing that attackers could exploit the browser’s GX Mods feature to inject malicious CSS across every webpage visited by a victim. This could enable cross-site data exfiltration and have a widespread impact on the browser. The research, published by zhero_web_security in 2026, demonstrates a zero-click…
-
Malicious Agent Skills Can Steal Credentials, Exfiltrate Source Code, and Install Backdoors
Malicious AI agent skills can be packaged to steal credentials, exfiltrate source code, and install backdoors while still bypassing many current skill-auditing systems. The paper finds that static scanners are especially weak against payload-preserving evasions, while runtime behavior auditing is far more resilient. The core threat is simple but serious: an agent skill is not…
-
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits.In a proof of concept, they reconstructed a signed-in user’s full Gmail address from a single visit, with no…
-
Hackers Use Server-Side Geofencing to Deliver Ousaban Banking Trojan in Spain and Portugal
A targeted campaign that delivers the Ousaban banking Trojan to users in Spain and Portugal using sophisticated server-side geofencing and multi-stage delivery. The adversary begins with a socially engineered phishing PDF that impersonates a corrupted document and coerces victims into visiting a malicious webpage through an “Atualizar” (Update) prompt. The PDF’s JavaScript is hex-escaped to…
-
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Scanners meant to catch malicious add-on “skills” for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology.Their strongest trick slipped past every scanner tested more than 90% of the time, and the…
-
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider.”The campaign remains active, and new malicious packages are likely to continue appearing as threat actors compromise…
-
TimbreStealer Malware Targets Mexico Companies With Advanced Evasion Techniques
A new campaign linked to the TimbreStealer information stealer that specifically targets Mexican companies, employing layered evasion and sophisticated runtime tricks to frustrate detection and analysis. Researchers Euler Neto and Cristóbal Tárraga detail behaviors that echo a 2024 Cisco Talos report while highlighting a notable variant: the use of DLL side”‘loading with unusually large malicious…
-
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft.According to JFrog, the packages “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core” mimic the legitimate “rollup-plugin-polyfill-node” project, down to the description, repository metadata, and First seen on thehackernews.com Jump…
-
Law enforcememt operation disrupted Malicious Residential Proxy Networks NetNut
Google disrupted NetNut, a major proxy network that routed internet traffic through compromised home devices used by cybercriminals. Google has disrupted NetNut, one of the world’s largest residential proxy networks. The service routed internet traffic through home devices, allowing customers to hide their real location and identity. >>Today, in coordination with the FBI, Lumen, and…
-
Hackers Use Fake API Documentation to Trick AI Agents Into Sending Crypto Payments
Hackers are now weaponizing documentation and site metadata to mislead autonomous AI agents into executing cryptocurrency payments. The attack leverages indirect prompt injection (IPI): malicious instructions hidden in web content and structured data that influence an AI agent’s reasoning during automated tasks. By combining SEO poisoning, JSON”‘LD abuse and CSS concealment, attackers create seemingly legitimate…
-
Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions
A widescale escalation in the PolinRider supply”‘chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts across 108 unique packages and extensions in npm, Packagist, Go modules, and a Chrome extension, linking this activity to the broader North Korean Contagious Interview…
-
New BioShocking Attack Tricks AI Browsers Into Leaking Credentials
LayerX found that BioShocking could trick AI browsers into leaking credentials by disguising malicious prompts as game rules. The post New BioShocking Attack Tricks AI Browsers Into Leaking Credentials appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-bioshocking-ai-browsers-leak-credentials/
-
Opera rolls out Paste Protect feature to fight ClickFix attacks
Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/opera-rolls-out-paste-protect-feature-to-fight-clickfix-attacks/
-
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT.Kaspersky said the activity is part of a “massive, multi-domain, multi-language” campaign that distributes malicious installer archives hosted on spoofed websites.These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others. First seen…

