Endpoint Security

Cybersecurity
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent access.
Application Security
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.
Cybersecurity
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome's TPM trust and cloud authenticator flows.
Application Security
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft capabilities.
Cybersecurity
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and steal credentials.
Cybersecurity
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
The DOUBLECUP Russian loader-as-a-service uses ClickFix prompts and PNG steganography in browser cache to deliver CountLoader and the DeviceManager RAT.
Cybersecurity
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
Bitdefender found fake Roblox Xeno Executor installers pushing a Java RAT that steals browser data, crypto wallets, game tokens, and payment data from players.
Cybersecurity
Coldcard Firmware Flaw Linked to $88.6M Bitcoin Sweep
A Coldcard firmware flaw that sent seed generation to a software PRNG is tied to an $88.6 million Bitcoin sweep across 4,585 drained wallet addresses.
CVE Vulnerability Alerts
N-able Warns Attackers Reached Managed Endpoints via N-central Flaw
N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.
Cybersecurity
DPRK macOS Malvertising Uses ClickFix to Steal Wallets and Cloud Keys
North Korea-linked actors use fake macOS update pages and ClickFix prompts to deploy malware that drains crypto wallets and steals SSH, AWS, and Azure keys.