ransomware Amadey, StealC malware operations disrupted in Operation Endgame action Operation Endgame, a coordinated law enforcement effort involving Microsoft, Europol, and international partners, successfully disrupted infrastructure used by the Amadey and StealC malware operations. The operation resu… BleepingComputer · Jun 24, 2026 High USCADKmalware-as-a-servicecredential theftransomware
supply-chain OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat This report details a significant supply chain attack leveraging OpenClaw’s Skill Marketplace, highlighting the emerging threat of AI agentic software. Malicious skills, including infostealers and evasion techniques, wer… Palo Alto Unit 42 · Jun 23, 2026 High USaiagenticsupply chain
malware New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently deploy the Atomic macOS Stealer (AMOS) infostealer, targeting users through fake CAPTCHA pages. The malware steals sensitive data like browser credenti… BleepingComputer · Jun 23, 2026 High USmacosclickfixinfostealer
ransomware The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is utilizing a sophisticated suite of EDR-terminating tools, centered around the GentleKiller framework, to disable security defenses before deploying ransomware. Th… The Hacker News · Jun 19, 2026 High RUSOWEransomware-as-a-serviceedr-killingbyovd
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
threat-intel Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats A coordinated malware campaign targeting JetBrains Marketplace plugins has emerged, with 15 malicious plugins designed to steal AI API keys from users. These plugins, posing as AI coding assistants, exfiltrate keys to a… The Hacker News · Jun 17, 2026 High USaiapimalware
threat-intel Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware North Korean APT37 group utilized a spear-phishing campaign mimicking Microsoft security alerts to deploy NarwhalRAT malware. The campaign leveraged urgency and confusion to trick victims into executing a malicious LNK f… The Hacker News · Jun 16, 2026 High NOSOspear-phishingratnorth korean
phishing Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts A coordinated phishing campaign, spearheaded by the now-disrupted Sniper Dz platform, targeted users in the Middle East and North Africa (MENA) through deceptive Facebook offers. The campaign leveraged browser notificati… The Hacker News · Jun 15, 2026 High DZALAEphishingsocial engineeringbrowser notifications
threat-intel ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories This week’s threat intelligence bulletin highlights several concerning developments, including a large-scale leak of identity records facilitated by infostealers, the emergence of a sophisticated MaaS RAT named SilabRAT… The Hacker News · Jun 11, 2026 High CVE-2026-49494USCHNOinfostealersmaas ratcredential theft
threat-intel Infostealers Turn Millions of Devices Into Credential Theft Machines This report details a significant increase in the use of infostealers as a primary method for attackers to steal credentials and gain unauthorized access to networks. Over 11.1 million devices were infected in 2025, resu… SecurityWeek · Jun 10, 2026 High IRinfostealerscredentialsmalware-as-a-service
threat-intel What 2026 DBIR Confirms: Attacks Are Living in the Browser The 2026 Verizon DBIR highlights a significant shift in cyberattacks, with a growing reliance on browser-based activities, particularly the unauthorized use of AI tools like ChatGPT and Gemini. Employees are increasingly… BleepingComputer · Jun 5, 2026 High USbrowseraicredential theft
threat-intel In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA This week’s cybersecurity news highlights a range of threats, including AI-powered attacks targeting computing power, ongoing Grandoreiro banking trojan campaigns, and a self-propagating ransomware group utilizing obfusc… SecurityWeek · Jun 5, 2026 High IRUSairansomwaresupply chain
malware Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS A sophisticated operation is impersonating popular open-source and freeware tools like Ghidra and dnSpy to lure users to malicious websites via a Traffic Distribution System (TDS). This TDS then delivers malware, includi… The Hacker News · Jun 4, 2026 High TRPLBRtdsmalware-as-a-serviceclick interception
threat-intel DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks A sophisticated cybercriminal operation, dubbed DriveSurge, has been hijacking thousands of legitimate websites to distribute malware, primarily through ClickFix and FakeUpdate attacks. The operation utilizes a traffic d… Dark Reading · Jun 2, 2026 High USmalwaretraffic distributionclickfix
threat-intel Why the browser is now the front line for AI security This BleepingComputer article highlights the escalating threat of AI-powered phishing attacks, primarily targeting the browser environment. Adversaries are leveraging AI to rapidly create and deploy phishing kits, automa… BleepingComputer · Jun 2, 2026 High USaiphishingbrowser
threat-intel 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees This article discusses the growing ‘shadow AI’ gap – where employees use unapproved AI tools connected to corporate data without IT oversight. With 69% of organizations acknowledging this issue, it highlights the disconn… The Hacker News · May 27, 2026 Medium aishadow aioauth
threat-intel Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers Akamai has acquired LayerX, a Tel Aviv-based startup, for $205 million to bolster its Zero Trust Network Access (ZTNA) portfolio. This move reflects a growing trend among cybersecurity vendors adding secure enterprise br… Dark Reading · May 22, 2026 Medium ILsecure browserztnasaas
malware Cross-Platform NPM Stealer, (Fri, May 22nd) A cross-platform Node.js stealer has been discovered targeting Windows, macOS, and Linux systems. The malware, obfuscated to avoid detection, extracts sensitive data from various browsers and applications, including Chro… SANS Internet Storm Center · May 22, 2026 High USstealerobfuscatedbrowser
threat-intel The New Phishing Click: How OAuth Consent Bypasses MFA In February 2026, a phishing-as-a-service platform, EvilTokens, compromised over 340 Microsoft 365 organizations across five countries by exploiting OAuth consent screens. Attackers gained access to valid refresh tokens… The Hacker News · May 19, 2026 High USGBoauthconsentphishing