Socket Uncovers 19 Malicious Chrome and Edge Extensions Stealing Crypto Wallets and Credentials
August 30, 2026 Socket researchers have uncovered a sprawling malware campaign hidden inside 19 browser extensions for Google Chrome and Microsoft Edge. Furthermore, the malicious framework steals cryptocurrency wallet secrets, harvests credentials, and…
ATF Confirms Major Cybersecurity Incident After Qilin Ransomware Breach Claim
August 27, 2026 The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a major cybersecurity incident on August 26, 2026, after the Qilin ransomware gang listed the U.S. federal law enforcement agency on its dark web data leak portal.…
ToxicPanda 2.0 Android Malware Abuses VPN and Wireless ADB
August 23, 2026 A critical vulnerability in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload executable PHP files for remote code execution on affected servers. Furthermore, the flaw has been actively disclosed and patched,…
MoYu Group Deploys Proxy Botnet Malware on Android Car Head Units via DoFun Update App
August 22, 2026 Kaspersky researchers have uncovered a supply-chain attack targeting Android-based car head units that uses a legitimate device-update app to spread proxy botnet malware. The operation, attributed to the MoYu threat actor group, marks the…
Sable Squirrel Spends Million on Expired Domains for Malware
August 16, 2026 A threat actor tracked as Sable Squirrel has spent nearly $7 million acquiring expired domains to build a sprawling criminal enterprise. Consequently, the group operates illegal sports streaming platforms, online gambling promotions, and…
Browser Assembled Malware Targets Crypto Traders and Investors
July 27, 2026 A massive malvertising operation dubbed SourTrade is using fake cryptocurrency and trading websites to turn victims’ browsers into local malware assembly lines. Threat actors leverage JavaScript, service workers, and a clean copy of…
OkoBot Malware Framework Deploys 20+ Payloads to Steal Crypto and Credentials
July 16, 2026 Kaspersky’s Global Research and Analysis Team has uncovered a sophisticated malware framework called OkoBot that delivers over 20 malicious payloads to steal cryptocurrency wallet seed phrases, browser credentials, and sensitive data.…
RedHook Android Malware Abuses Wireless ADB for Shell Access
July 12, 2026 Group-IB researchers have uncovered a major upgrade to the RedHook Android malware that abuses Wireless ADB to gain shell privileges on devices without needing a computer connection. Consequently, the threat significantly expands what…
Mastra npm Supply Chain Attack: 144 Packages Compromised
June 17, 2026 On June 17, 2026, a software supply chain attack codenamed “easy-day-js” compromised 144 npm packages associated with the Mastra AI framework. Attackers hijacked a former contributor’s account to publish malicious versions…
ChatGPT LLMShare Malware Campaign Abuses Share Links to Deliver Fake Outage Pages
June 1, 2026 Threat actors have launched a novel malware campaign dubbed LLMShare that abuses legitimate ChatGPT share links to deliver malicious payloads. The campaign uses ChatGPT’s own code-rendering feature to host fake outage pages on trusted…