Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Cyber Security News
cybersecuritynews.com > fake-claude-and-chatgpt-installers

Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware

2+ day, 17+ hour ago   (629+ words) Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a macOS password stealer. The campaign relies on persuasion instead of a software flaw. A visitor…...

gbhackers.com
gbhackers.com > clickfix-lures-target-macos

Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.

2+ day, 19+ hour ago   (593+ words) The campaigns do not require a macOS vulnerability; instead, they abuse user trust by persuading victims to paste attacker-controlled commands into Terminal, sidestepping traditional file-centric protections. However, Russian-language artifacts observed in some samples do not establish attribution to a particular…...

@varindiamag
varindia.com > news > infostealers-hijack-claude-sessions

Infostealers Hijack Claude Sessions

3+ day, 14+ hour ago   (33+ words) varindia.com Infostealers Hijack Claude Sessions See What’s Next in Tech With the Fast Forward Newsletter Nothing to see here - yet When they Tweet, their Tweets will show up here....

eSecurity Planet
esecurityplanet.com > news > news-weedhack-fake-minecraft-malware

WeedHack Malware Persists as Fake Minecraft Sites Survive C2 Disruption

4+ day, 16+ hour ago   (404+ words) Fake Minecraft sites continue distributing WeedHack malware through SEO poisoning and trusted hosting platforms despite disruption of its original C2 infrastructure. Disrupting WeedHack’s command-and-control infrastructure did not stop its distribution. Fake Minecraft client sites and trusted hosting services continued serving the…...

SiliconANGLE
siliconangle.com > 09/08/2026 > clickfix-moves-into-the-browser-and-onto-webdav-cisco-talos-finds

ClickFix moves into the browser and onto WebDAV, Cisco Talos finds

4+ day, 17+ hour ago   (448+ words) UPDATED 06:00 EDT / SEPTEMBER 08 2026 Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the copy-and-paste PowerShell prompt it is known for, one that never touches the operating system at all and one…...

kobaran.com
kobaran.com > shai-hulud-malware-returns-to-npm-unchanged-111-days-after-its-hash-was-fingerprinted

Shai-Hulud Malware Returns to npm Unchanged, 111 Days After Its Hash Was Fingerprinted

4+ day, 17+ hour ago   (507+ words) Four packages is a small blast radius next to the 639 malicious versions pushed during the May campaign. The significance sits elsewhere. npm rolled out publish-time scanning in July, a control that briefly holds new publications for automated analysis before they…...

MSSP Alert
msspalert.com > brief > new-synkloader-malware-distributed-via-microsoft-teams-phishing

New SynkLoader malware distributed via Microsoft Teams phishing

5+ day, 11+ hour ago   (109+ words) The SynkLoader malware operates through a multi-stage process, beginning with convincing Microsoft Teams messages that mimic IT support communications. These messages aim to lure recipients into downloading and executing malicious files. Once activated, SynkLoader presents a fake Windows lock screen,…...

Google News
cyberpress.org > fake-minecraft-mod-backdoor

Fake Minecraft Mod Steals Passwords and Gives Hackers Remote Control of PCs

5+ day, 17+ hour ago   (365+ words) Cybersecurity researchers have uncovered a fake Minecraft optimisation mod that steals browser passwords, payment-card data, cookies, Discord information, and system details while giving attackers remote control over infected Windows PCs. The malicious Java Archive (JAR) pretends to be Lithium Extras…...

Security Affairs
securityaffairs.com > 198573 > malware > jsceal-hides-crypto-malware-in-v8-bytecode.html

JSCeal Hides Crypto Malware in V8 Bytecode

5+ day, 16+ hour ago   (764+ words) Why AI Agent Sandboxes Are Failing Security Tests Berlin Ransomware Leak Exposes State Secrets Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure Security Affairs newsletter Round 593 by…...

The Hacker News
thehackernews.com > 2026 > 09 > jsceal-malware-can-bypass-google.html

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

5+ day, 15+ hour ago   (494+ words) Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components. As recently as last month, ad security platform Confiant…...