Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
4+ day, 9+ hour ago (629+ words) Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a macOS password stealer. The campaign relies on persuasion instead of a software flaw. A visitor…...
Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
4+ day, 11+ hour ago (593+ words) The campaigns do not require a macOS vulnerability; instead, they abuse user trust by persuading victims to paste attacker-controlled commands into Terminal, sidestepping traditional file-centric protections. However, Russian-language artifacts observed in some samples do not establish attribution to a particular…...
WeedHack Malware Persists as Fake Minecraft Sites Survive C2 Disruption
6+ day, 8+ hour ago (404+ words) Fake Minecraft sites continue distributing WeedHack malware through SEO poisoning and trusted hosting platforms despite disruption of its original C2 infrastructure. Disrupting WeedHack’s command-and-control infrastructure did not stop its distribution. Fake Minecraft client sites and trusted hosting services continued serving the…...
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
6+ day, 4+ hour ago (1507+ words) Following the initial investigation, we decided to hunt for similar WebDAV and ordinal-execution patterns in an attempt to recover the full infection chain. Using VirusTotal, we were able to identify a full chain from a second DLL loader named "pf....
ClickFix moves into the browser and onto WebDAV, Cisco Talos finds
6+ day, 8+ hour ago (448+ words) UPDATED 06:00 EDT / SEPTEMBER 08 2026 Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the copy-and-paste PowerShell prompt it is known for, one that never touches the operating system at all and one…...
PoisonedRefresh Malware Hides Inside Apache Memory While F5 BIG-IP Files Stay Clean
6+ day, 19+ hour ago (546+ words) A conventional web shell is a small PHP, JSP, or ASP script dropped into a directory the web server can reach. That approach is noisy by design. It leaves behind modified files, unexpected scripts, changed hashes, and odd POST parameters,…...
Fake software installers use msiexec to bypass defenses and persist on Windows – 4sysops
1+ week, 2+ hour ago (21+ words) Microsoft is tracking an active fake software campaign that regenerates malicious archives behind familiar download filenames, then uses Windows components such...
New SynkLoader malware distributed via Microsoft Teams phishing
1+ week, 3+ hour ago (109+ words) The SynkLoader malware operates through a multi-stage process, beginning with convincing Microsoft Teams messages that mimic IT support communications. These messages aim to lure recipients into downloading and executing malicious files. Once activated, SynkLoader presents a fake Windows lock screen,…...
Fake Minecraft Mod Deploys Myth Stealer RAT to Steal Browser Credentials and Cookies
1+ week, 8+ hour ago (627+ words) A counterfeit Minecraft optimisation mod is installing Myth Stealer, malware that can steal browser passwords, cookies and data. Its malicious file looks useful because features work as advertised, giving players little reason to suspect a hidden threat. The campaign exploits…...
Fake Minecraft Mod Steals Passwords and Gives Hackers Remote Control of PCs
1+ week, 9+ hour ago (365+ words) Cybersecurity researchers have uncovered a fake Minecraft optimisation mod that steals browser passwords, payment-card data, cookies, Discord information, and system details while giving attackers remote control over infected Windows PCs. The malicious Java Archive (JAR) pretends to be Lithium Extras…...