Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Path of Exile 2 can complete login and character selection normally, then fail as soon as the next area begins loading. The ...
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the ...
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
First phishing, then a fake captcha and a terminal command – this is how the cyberattack on Berlin proceeded, according to ...
GitHub Copilot's app now runs coding agents inside WSL, and Google confirms WSL and native Windows support are both coming to ...
Crooks are deploying cheeky browser-in-the-browser techniques to trick victims into downloading RMM tools.
Static application security testing, or SAST, is most useful when it is close to the way your team actually writes code. That is where Semgrep becomes valuable. It can scan source code quickly, fit ...
BlueMoon exploit kit, shared by four China-linked spy groups in 12 days, chains Chrome and Windows zero-days to hand ...
Chrome zero-day CVE-2026-85046 is under active attack as the sixth actively exploited Chrome vulnerability of 2026. A type confusion flaw in Chrome's V8 JavaScript engine lets attackers run code ...