threat-intel Quand les fuites de données ciblent les victimes This article highlights a concerning trend where data breaches are increasingly used to generate actionable intelligence for criminal activity, particularly targeting wealthy individuals with crypto assets and luxury goods. French authorities are investigating a case where stolen tax data linked to cryptocurrency holde… ZATAZ · 2d ago High FRdata-breachcryptocurrencyphysical-attacks
threat-intel 2,3 millions de détenteurs crypto français ciblés A ZATAZ report has uncovered two separate cybercrime listings offering access to a database of 2.3 million French cryptocurrency holders, containing sensitive information like identities, contact details, addresses, and… ZATAZ · 3d ago High FRcryptokidnappingdata-breach
threat-intel QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer A long-standing supply chain attack targeting QuickFox, a VPN tool used by overseas Chinese users, has been ongoing since August 2025. The attack, attributed to tactical overlaps with the Chinese state-sponsored threat a… The Hacker News · Aug 5, 2026 High CNsupply-chainmalwarechina
threat-intel Fake IRS letters target cryptocurrency holders Scammers are impersonating the IRS to trick cryptocurrency holders into visiting fake websites designed to steal their personal information and digital assets. The IRS does not operate a Digital Asset Compliance Portal,… Graham Cluley · Aug 4, 2026 High HOROphishingcryptocurrencyfraud
supply-chain Risk Ledger Raises $32 Million in Series B Funding Risk Ledger, a UK-based supply chain security firm, secured $32.3 million in Series B funding to expand its network and enhance its AI-powered risk intelligence platform. This investment will allow them to grow their use… SecurityWeek · Jul 17, 2026 Info GBsupply chaincybersecurityrisk management
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
threat-intel Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages Threat actors compromised the Injective Labs GitHub repository and injected a malicious npm package designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. The package, disguised as telemetry func… The Hacker News · Jul 10, 2026 High npmsupply-chaincryptocurrency
ransomware New Avalon Malware Framework Packs CrownX Ransomware Capabilities Researchers at Blackpoint Cyber discovered Avalon, a new modular malware framework used to deploy the CrownX ransomware. The framework utilizes a multi-stage phishing campaign to bypass security controls and performs cre… The Hacker News · Jul 3, 2026 High CVE-2025-3248USphishingcredential theftlateral movement
phishing Bluekit phishing kit adopts browser-in-the-middle for login theft Bluekit, a phishing-as-a-service platform, has evolved by incorporating browser-in-the-middle (BitM) capabilities, allowing it to steal login credentials more effectively. The platform utilizes the rrweb JavaScript libra… BleepingComputer · Jun 25, 2026 High USphishingbitmbrowser-in-the-middle
malware New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently deploy the Atomic macOS Stealer (AMOS) infostealer, targeting users through fake CAPTCHA pages. The malware steals sensitive data like browser credenti… BleepingComputer · Jun 23, 2026 High USmacosclickfixinfostealer
supply-chain Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer A sophisticated supply chain attack targeting Laravel-Lang PHP packages has been identified, involving the mass modification of Git tags to inject a cross-platform credential-stealing framework. The attacker leveraged co… The Hacker News · May 23, 2026 Critical USsupply-chaincredential-stealingphp