
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to

Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to

A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others’ meeting data and potentially join calls,

Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft

Threat actors poisoned Xanadu’s mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research

FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.

Attackers tampered with Adform’s trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.

Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant

A state-sponsored campaign used hacked South Korean websites to exploit an AnySign4PC zero-day and infect visitors with SIGNBT and COPPERHEDGE

Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor’s credentials.

Researcher Håkon Måløy showed hidden Word prompts can make Microsoft Copilot alter figures and propagate instructions into new documents despite
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.