threat-intel 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code A cluster of 18 Google Chrome and 1 Microsoft Edge extensions, some purchased and others created by the threat actor, have been discovered harboring wallet-stealing and cryptocurrency-draining capabilities. The campaign, dubbed ‘Superior’ by Socket, has been active since February 2024 and involves acquiring legitimate… The Hacker News · 2d ago High extensionmalwarewallet
supply-chain Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Two men from Western Australia have been charged in connection with TeamPCP, a cybercriminal group responsible for a global supply-chain hacking campaign that targeted over 1000 organizations, including OpenAI and the Eu… Graham Cluley · 2d ago High AUsupply chainopen sourcemalware
threat-intel ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged compromised credentials and utilized a… SANS Internet Storm Center · 2d ago High phishingcredential theftspear-phishing
threat-intel Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks Australian authorities have charged two men linked to the cybercrime group TeamPCP, allegedly responsible for a widespread supply chain attack targeting over 1,000 organizations globally. The group exploited compromised… The Hacker News · 3d ago High AUsupply chaincredential theftopen source
threat-intel Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools A new campaign targeting Cambodia is utilizing a sophisticated multi-stage attack leveraging a vulnerable OPSWAT driver to deploy the open-source remote access trojan, Spark RAT. Attackers are using deceptive phishing em… The Hacker News · 3d ago High CVE-2026-36425KHphishingransomwaremalware
threat-intel Threat landscape for industrial automation systems. Q2 2026 In Q2 2026, the percentage of ICS computers blocked by malicious objects continued to decline, hitting a low of 19.15%, the lowest since 2022. East Asia and Africa saw significant increases in threat percentages across… Securelist · 3d ago High RUCHAFicsindustrial automationcybersecurity
threat-intel JavaScript obfuscation: From party trick to phishing kit This article from Cisco Talos explores the techniques used to obfuscate JavaScript code, primarily for malicious purposes like phishing and malware delivery. The author details various methods of hiding code, including s… Cisco Talos · 3d ago High obfuscationjavascriptmalware
threat-intel GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address Threat actors linked to Dark Caracal have deployed a new Go-based malware framework, GoCaracal, utilizing an Ethereum smart contract to dynamically update its command-and-control (C2) address. This allows operators to ch… The Hacker News · 3d ago Medium BRECCHethereumsmart contractc2
threat-intel Dark Caracal Adds New Malware to Cyber Espionage Arsenal The Dark Caracal cyber-espionage group, linked to Lebanon, has added a new modular malware framework called GoCaracal to its arsenal. This framework, developed since 2026, is used for data theft, maintaining persistent a… Dark Reading · 4d ago High LBVEBRcyber-espionagedata theftmalware
threat-intel Android Malware Hijacks Update System for Car Head Units Threat actors, linked to the BadBox click-fraud botnet, are exploiting legitimate update mechanisms in car head units to spread malware. This marks the first known instance of malware targeting automotive infotainment sy… Dark Reading · 4d ago High CHandroidbotnetmalware
threat-intel AI Speeds Up Malware Development, Not Its Success Rate: Analysis A Palo Alto Networks Unit 42 analysis of 405 AI-linked malware samples revealed that while AI is accelerating malware development, it hasn't significantly improved the malware's ability to evade detection. The majority o… SecurityWeek · 4d ago Medium CHUNaimalwaresandbox
threat-intel 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's inf… The Hacker News · 5d ago High npmphishingmalware
threat-intel First Malware Built Specifically for Car Head Units Fuels Botnet Researchers at Kaspersky have identified a new malware specifically designed for car head units, linked to the BadBox botnet. This represents a significant expansion of the BadBox threat, which has previously targeted An… SecurityWeek · 5d ago High CNbotnetmalwaresupply-chain
threat-intel The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution A recent analysis by Palo Alto Unit 42 found that while a significant number of AI-enabled malware samples exist in research and testing environments, only a small fraction (around 12) reached production endpoints across… Palo Alto Unit 42 · 5d ago Medium USCNGBaimalwarethreat intelligence
threat-intel Crooks push Mac malware through fake OpenAI Codex ads Russian threat actors are leveraging fake OpenAI Codex advertisements to distribute malware targeting macOS users. The campaign uses a malicious installer disguised as a legitimate tool, aiming to compromise systems and… The Register · 5d ago Medium RUmacphishingmalware
threat-intel Foul Language: WordlistLoader Disguises Malware as Ordinary Text A new malware loader called WordlistLoader is being used to deliver the Amatera infostealer, primarily through ClickFix-style campaigns. WordlistLoader disguises malicious code using lists of ordinary English words, allo… Dark Reading · 6d ago High malwareloaderinfostealer
threat-intel Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning Cybersecurity researchers at McAfee Labs have identified a campaign where malicious websites disguised as legitimate Minecraft clients are distributing the Weedhack malware. These sites, leveraging SEO poisoning and mimi… The Hacker News · 6d ago Medium seo poisoningmalwareminecraft
threat-intel Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials A campaign of malicious Firefox add-ons, dubbed the "Offside Wallet Theft Factory", has been quietly stealing cryptocurrency wallet seed phrases and browser credentials since March 2026. Researchers identified 40 out of… Graham Cluley · 6d ago High browsercryptomalware
threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware
threat-intel WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade det… The Hacker News · 6d ago High phishingransomwaremalware