neko-tanuki-furoshiki feed
2026-09-24
- The Psychedelic Stealer: When a CAPTCHA Becomes an InstallerArctic Wolf
- CARBONATO: a botnet built around an AI agent | ThreatDownBleepingComputer
- A Wretch Client: From ClickFix deception to information stealer deploymentDarkReading
- Converging Ransomware Tradecraft: Analysis of a Multi-Phase Attack | BridewellDarkReading
- Distribution of SectopRAT (ArechClient2) Disguised as Notion Installer - ASECDarkReading
- Uncovering a SectopRAT Variant Embedded in Legitimate Software | FortiGuard LabsDarkReading
- Uncovering a SectopRAT Variant Embedded in Legitimate SoftwareFortinet
- VelvetCake: Konni Targets Ukraine With Malicious LNK Filesgbhackers.
- MacSync under the microscope: new delivery methods and a new payloadSecurelist
- A malicious npm package hidden three dependencies deep: the ulid-xyz delivery chain - Real-time OpenThe Hacker News
- Chatbot Conundrum: Phishing Attempts of OpenAI’s ChatGPTThe Hacker News
- ClickFix Attack: How ClickFix Malware Scam Works | Group-IBThe Hacker News
- Deep-Live-Cam Supply Chain Attack: Technical Analysis - Real-time Open Source Software Supply ChainThe Hacker News
- Diesel Vortex phishing operation targeting freight - Have I Been SquattedThe Hacker News
- Diesel Vortex: Exploring connections to Russian LLCs - Ctrl-Alt-IntelThe Hacker News
- Exvicy: A Copycat of the ErrTraffic Malware Distribution FrameworkThe Hacker News
- From Payment Plan to Ransomware - Inside a Global Group AttackThe Hacker News
- Inside Corp MDM, the Android spyware targeting logistics companies - Have I Been SquattedThe Hacker News
- Placeholder Domains Whose Ads Serve ScamsThe Hacker News
- RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theft - BlackpThe Hacker News
2026-09-23
- AI Agents Are Hacking Online Retailers for $25 a CompanyBleepingComputer
- RemControl: AI Built the Overlays. Victims Lose their PINs | Group-IB BlogBleepingComputer
- third-party.com Placeholder Domain Now Serves ClickFixBleepingComputer
- Disposable Domains, Durable Hosting — ActiveSOC Bloggbhackers.
- New PamStealer variant targets macOS via fake crypto walletgbhackers.
- Graphalgo Malware Spreads to Terraform and GoThe Hacker News
- How DPRK’s Contagious Interview Campaign Targets Developers - Kudelski Security Research CenterThe Hacker News
- MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack | SocketThe Hacker News
- MemTensor npm and PyPI Packages Hit by a Go Worm - Real-time Open Source Software Supply Chain SecurThe Hacker News
- Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes - StepSecurityThe Hacker News
- Why Does an npm Math Library Need an Encrypted Loader? - Real-time Open Source Software Supply ChainThe Hacker News
2026-09-22
- DarkMe RAT: A VB6 APT Trojan Turned Conventional InfostealerHuntress Labs
- Cloudflare participates in global operation to disrupt EvilTokens Phishing-as-a-Service | CloudflareThe Hacker News
- EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFAThe Hacker News
- PolinRider Spreads Through Compromised GitHub Accounts and Packagist | SocketThe Hacker News
2026-09-21
- Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPOSecurelist
- Beyond Lazarus: How North Korea Organizes Its Cyber OperationsThe Hacker News
- ChainScript: Tracing a Node.js RAT Through the Blockchain - Blackpoint CyberThe Hacker News
- LLMShare: using shared chatbot pages to distribute malwareThe Hacker News
- PasteSwitch Clickfix Operation Compromises HBO on RedditThe Hacker News
- Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign | Trend MicroThe Hacker News
- Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a DistriThe Hacker News
- When Trust Becomes the Payload in a Fake Codex ClickFix Campaign| Cato NetworksThe Hacker News
- Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day ExploitsVolexity
2026-09-19
2026-09-18
- Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto TieSentinelOne
- Operation RapidRust: New APT36 Malware Tools | ThreatLabzThe Hacker News
- PhantomRaven: LLM-generated Information Stealer for Bug Bounty HuntingThe Hacker News
- Tech Note - BeaverTail variant distributed via malicious repositories and ClickFix lure - GitLab SecThe Hacker News
2026-09-17
- Beware the SparroWock: The backdoor that bites, the commands that catchESET WeLiveSecurity
- The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised tSecurelist
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin AmericaThe Hacker News
- Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard LabsThe Hacker News
- Dark Web Profile: Handala HackThe Hacker News
- HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack | Group-IB BlogThe Hacker News
- Iranian cyber targeting of dissidents, activists and journalists | National Cyber Security CentreThe Hacker News
- SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central AThe Hacker News
- SloppyRAT: A New Tool For Ransomware Attacks | ThreatLabzThe Hacker News
- Untracked Nightmares: The Threats Hiding Behind Commodity InfrastructureThe Hacker News
2026-09-16
2026-09-15
2026-09-14
2026-09-11
2026-09-10
- Casbaneiro: A Banking Trojan with Distributed Data-Receiving ServersFortinet
- Protecting organizations from AI-assisted executive impersonation and invoice fraudMicrosoft Security Blog
- The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIREUnit42(Palo Alto Networks)
2026-09-09
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilitiesCisco Talos
- Grand Theft Auto VI hype leads to malwareHuntress Labs
- Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM PersistenceHuntress Labs
- Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like ActivityHuntress Labs
- Passkey-themed social engineering leads to identity and cloud compromiseMicrosoft Security Blog
- Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using ChrProofPoint
- Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & WindowsVolexity
2026-09-08
- Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a TrustDarkReading
- ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport ManagerDarkReading
- ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2DarkReading