
Fake OpenAI Repo Trended on Hugging Face Before Malware Found
A fraudulent OpenAI repository reached Hugging Face’s trending list while distributing infostealing malware targeting credentials and access tokens.

A fraudulent OpenAI repository reached Hugging Face’s trending list while distributing infostealing malware targeting credentials and access tokens.

Attackers chain Google sponsored ads with fake Claude.ai chat sessions to deliver MacSync, a macOS infostealer harvesting Keychain contents and

Kaspersky discovered DAEMON Tools versions 12.5.0.2421–12.5.0.2434 were backdoored on the official site for one month, infecting thousands across 100+ countries

Attackers compromised DigiCert support staff via a chat-delivered screenshot, used their access to obtain code-signing certificates, and signed Zhong Stealer

Threat actors are systematically abusing Amazon SES to send phishing emails that pass SPF, DKIM, and DMARC checks — turning

Claude Desktop’s unauthorized modifications may breach EU laws on clear user consent.

Microsoft awarded $2.3 million to researchers during this year’s Zero Day Quest for discovering vulnerabilities.

Capsule Security emerges from stealth with $7 million funding to secure AI agents.

French mother and child rescued after 20-hour kidnap, exposing extortion threats tied to crypto wealth.

OpenAI confronts potential compromise of macOS code signing certificate due to North Korean-linked Axios supply chain attack.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.