Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.
1+ hour, 24+ min ago (589+ words) Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning developer infrastructure into a phishing delivery layer. OX Security said it identified 24 malicious npm packages containing identical HTML code designed to…...
NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding
2+ hour, 49+ min ago (669+ words) A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents through a single visit to a malicious website. Researchers Elad Luz and Ofek Itach from Oasis Security discovered that…...
WhatsApp Passkeys Now Protect Over 1 Billion Users Against Account Takeover Attacks
7+ hour, 28+ min ago (497+ words) WhatsApp has announced that over one billion people now use passkeys to secure their accounts, enhancing phishing-resistant authentication across one of the world’s largest messaging platforms. This update, revealed on August 25, introduces support for multiple passkeys, stronger two-step verification credentials,…...
WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption
1+ day, 6+ hour ago (574+ words) The researchers found multiple active websites impersonating popular Minecraft projects, offering paid clients at no cost, and abusing well-known hosting platforms to make malicious downloads appear trustworthy. McAfee WebAdvisor blocked more than 6,300 attempts to visit these malicious sites in the…...
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
1+ day, 5+ hour ago (548+ words) Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey Microsoft device-code phishing kit. Its…...
Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages
1+ day, 22+ hour ago (615+ words) Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to security scanners while serving credential-harvesting banking portals to genuine search users. Unlike conventional phishing operations that push malicious links…...
macOS ClickFix Crimekit Uses Polygon Smart Contracts to Deploy AMOS Stealer and XMRig Miner
2+ day, 5+ hour ago (489+ words) A macOS-focused ClickFix campaign is abusing Polygon smart contracts to conceal its live command-and-control infrastructure while deploying an Atomic macOS Stealer (AMOS) variant, a persistent backdoor, and an XMRig cryptominer. The command decodes to a curl | bash pipeline that retrieves…...
768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts
4+ day, 5+ hour ago (525+ words) A large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and cloud billing fraud. The credentials include…...
Zero-Click Grok Attack Lets Hackers Steal Chat History Using Encrypted Prompt Injection
4+ day, 4+ hour ago (548+ words) A newly disclosed prompt-injection technique could turn a routine request to summarize a webpage in xAI’s Grok web chat into a silent data-exfiltration attack, potentially exposing a user’s name, approximate location, subscription tier, and active conversation history. Security researchers at…...
Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords
5+ day, 1+ hour ago (464+ words) A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing bank-payment lure with a fileless execution chain that keeps the final malware…...