Trojanized npm Packages Deliver AI Powered RedC2 4.0 Linux Backdoor
Cybersecurity researchers discovered 14 npm packages hiding RedC2 4.0 Linux backdoor with AI assisted C2 capabilities, enabling post exploitation activities.
Cybersecurity researchers discovered 14 npm packages hiding RedC2 4.0 Linux backdoor with AI assisted C2 capabilities, enabling post exploitation activities.
Infoblox has revealed that threat actors are spending millions of dollars on expired domains to inherit trusted reputations and redirect users to scams, gambling platforms and malware infrastructure.
Cybersecurity groups have warned WhatsApp users about the PKH 500000 scam, a phishing campaign that attempts to steal personal information, banking details, and WhatsApp accounts through fraudulent messages.
SOCRadar has uncovered DOUBLECUP, a Russian loader as a service that uses ClickFix, steganographic PNG images, and advanced evasion techniques to deliver CountLoader and DeviceManager RAT.
Security researchers have identified three attack techniques targeting Google Password Manager on Windows that could allow malware to compromise passkey protected accounts after an initial device infection.
This week’s cybersecurity roundup highlights AI powered attacks, hundreds of Chrome security fixes, SonicWall credential stuffing, DNS hijacking, ransomware campaigns, and emerging malware threats.
Researchers uncovered a North Korea linked macOS malvertising campaign that uses fake software updates, ClickFix techniques, and blockchain based command infrastructure to deploy cryptocurrency stealing malware.
CERT UA has warned of a phishing campaign by UAC 0099 that uses a fake Notepad++ plugin to deploy MATCHBOIL.V2 malware and establish persistent access on Windows systems.
Group IB uncovered a China nexus cyber operation using the new TriBack Loader to target government, healthcare, and education organizations across Asia and Latin America through phishing and exploitation of known vulnerabilities.
Researchers have uncovered the SleeperGem software supply chain attack involving malicious RubyGems packages designed to compromise developer machines and establish persistent access.