Push Security has uncovered a new AiTM phishing campaign targeting TikTok for Business accounts using Google and TikTok themed login pages
Flux RSS
— Sources secondairesHalcyon and Beazley Security track the return of Iranian ransomware group Pay2Key
Python package LiteLLM compromised with credential-stealing malware linked to TeamPCP threat group
Silver Fox pivots from ValleyRAT tax lures to WhatsApp‑style stealers, blending espionage & phishing
Ghost npm campaign fakes install logs to steal sudo passwords and drop RATs that loot crypto and data
Russian cybercriminal Aleksei Volkov has received close to seven years behind bars for role in Yanluowang ransomware
Tycoon2FA phishing platform resumes activity post-takedown, leveraging AITM techniques to bypass MFA
New Trivy Docker images 0.69.5 and 0.69.6 compromised with TeamPCP infostealer, impacting CI/CD scans
Mobile banking malware targets over 1200 financial apps globally, shifting fraud to user devices
ShieldGuard Chrome extension posed as a crypto security tool but stole wallets and drained user data
Some of these campaigns are linked to Darcula, a Chinese-language phishing-as-a-service platform
The FBI wants to hear from gamers who have downloaded Steam titles containing malware
PixRevolution Android trojan hijacks Brazil’s PIX payments in real time using accessibility abuse
The pro-Iran Handala group claims to have wiped 200,000 systems in destructive wiper malware attack on US firm Stryker
Over 250 legitimate websites, including news outlets and a US Senate candidate’s official webpage, been compromised to infect visitors with infostealers, warn Rapid7 researchers
BlackSanta malware targets HR staff with fake resumes, kills EDR and steals system data
A bank, an airport, a non-profit and the Israeli branch of a US software company were among the targets of this new MuddyWater campaign
Almost a quarter of the zero days detected by Google in 2025 targeted security and networking appliances
Ox Security warns that Mail2Shell could enable threat actors to hijack FreeScout systems without user interaction
Malware campaign uses Ukrainian email service for credibility, deploying "BadPaw" to execute attacks