
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent

Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent

Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to

Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome’s TPM trust and

Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft

Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and

The DOUBLECUP Russian loader-as-a-service uses ClickFix prompts and PNG steganography in browser cache to deliver CountLoader and the DeviceManager RAT.

Bitdefender found fake Roblox Xeno Executor installers pushing a Java RAT that steals browser data, crypto wallets, game tokens, and

A Coldcard firmware flaw that sent seed generation to a software PRNG is tied to an $88.6 million Bitcoin sweep

N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.

North Korea-linked actors use fake macOS update pages and ClickFix prompts to deploy malware that drains crypto wallets and steals
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.