ACR Stealer is targeting enterprises through ClickFix lures, PowerShell scripts, blockchain services, and malicious image ...
UAC-0145 uses fake CAPTCHA checks on compromised sites to push Windows malware, while COWARDDUCK backdoors Android devices ...
HalluSquatting exploits AI coding assistants that hallucinate fake repository names, letting attackers register those names ...
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication ...
It's an absolute beast with over 700 fixes and active zero-days landing right as major SQL and SharePoint versions hit end of ...
Attackers were found using a Lua-based malware loader posing as a TrueType font tile, with layered obfuscation and fileless ...
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer ...
A large-scale phishing operation has been observed disguising a malicious script as a TrueType font file (.tff). Using the ...
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint ...
Right on the heels of Microsoft releasing a record number of security patches, a researcher has published exploit code that ...
A fake GitHub repository campaign created hundreds of malicious projects that impersonated legitimate software and cybersecurity tools. The repositories directed users to deceptive download pages that ...
A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to ...