Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
3+ day, 2+ hour ago (629+ words) Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a macOS password stealer. The campaign relies on persuasion instead of a software flaw. A visitor…...
F5 BIG-IP malware hides web shells in memory to evade detection
3+ day, 16+ hour ago (78+ words) scworld.com F5 BIG-IP malware hides web shells in memory to evade detection An In-Depth Guide to Network Security MikroTik routers targeted by active SSH zero-day exploitation Cisco addresses critical vulnerabilities in Nexus 9000 switches and IOS XR HPE patches ArubaOS-CX switches…...
Claude Hacked? Info-stealing malware steals tokens from subscribers
4+ day, 8+ hour ago (565+ words) Basic Tutorials What happened in the Claude attacks? The debate was sparked by the case of Grant De Swardt, an independent AI consultant from East Sussex in the UK, as reported by TechCrunch. De Swardt uses Claude agents professionally to…...
WeedHack Malware Persists as Fake Minecraft Sites Survive C2 Disruption
5+ day, 1+ hour ago (404+ words) Fake Minecraft sites continue distributing WeedHack malware through SEO poisoning and trusted hosting platforms despite disruption of its original C2 infrastructure. Disrupting WeedHack’s command-and-control infrastructure did not stop its distribution. Fake Minecraft client sites and trusted hosting services continued serving the…...
npm Supply Chain Worm Returns After Four-Month Dormancy With Same Malicious Payload
5+ day, 6+ hour ago (330+ words) A previously documented Shai-Hulud npm supply-chain worm payload has reportedly reappeared after 111 days of inactivity, using the exact same malicious file linked to the May 19 compromise of hundreds of @AntV package versions. The reactivation raises concerns about registry-level malware detection…...
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
4+ day, 21+ hour ago (1507+ words) Following the initial investigation, we decided to hunt for similar WebDAV and ordinal-execution patterns in an attempt to recover the full infection chain. Using VirusTotal, we were able to identify a full chain from a second DLL loader named "pf....
Shai-Hulud Malware Returns to npm Unchanged, 111 Days After Its Hash Was Fingerprinted
5+ day, 2+ hour ago (507+ words) Four packages is a small blast radius next to the 639 malicious versions pushed during the May campaign. The significance sits elsewhere. npm rolled out publish-time scanning in July, a control that briefly holds new publications for automated analysis before they…...
PoisonedRefresh Malware Hides Inside Apache Memory While F5 BIG-IP Files Stay Clean
5+ day, 12+ hour ago (546+ words) A conventional web shell is a small PHP, JSP, or ASP script dropped into a directory the web server can reach. That approach is noisy by design. It leaves behind modified files, unexpected scripts, changed hashes, and odd POST parameters,…...
Fake Minecraft Mod Deploys Myth Stealer RAT to Steal Browser Credentials and Cookies
6+ day, 1+ hour ago (627+ words) A counterfeit Minecraft optimisation mod is installing Myth Stealer, malware that can steal browser passwords, cookies and data. Its malicious file looks useful because features work as advertised, giving players little reason to suspect a hidden threat. The campaign exploits…...
Fake Minecraft Mod Steals Passwords and Gives Hackers Remote Control of PCs
6+ day, 2+ hour ago (365+ words) Cybersecurity researchers have uncovered a fake Minecraft optimisation mod that steals browser passwords, payment-card data, cookies, Discord information, and system details while giving attackers remote control over infected Windows PCs. The malicious Java Archive (JAR) pretends to be Lithium Extras…...