JINX-0164 Targeting virtual currency companies with fake recruiting lure and macOS malware

Rabi LakshmananMay 28, 2026Supply chain attacks/malware A new campaign, orchestrated by a previously undocumented threat actor, targets crypto organizations with the goal of facilitating the theft of digital assets using recruitment-themed social engineering and custom-built macOS malware. “These campaigns utilized advanced social engineering techniques, custom macOS malware, and deep targeting of CI/CD infrastructure,” said Wiz […]

Grandoreiro malware and BTMOB RAT campaign targets Windows and Android users

Latin America and Europe have been targeted by two banking Trojan campaigns aimed at infecting Windows and Android devices with Grandoreiro and BTMOB malware, respectively. This is according to new research published by WatchGuard and ESET, who observed these two malware families being used to identify companies in Spain, Portugal, and Mexico, as well as […]

Malicious npm package stole files from Claude AI user directory via GitHub

Rabi LakshmananMay 27, 2026Threat Intelligence/Supply Chain Attacks Cybersecurity researchers have discovered a new malicious package on the npm registry with information-stealing capabilities. According to OX Security, the package, named mouse5212-super-formatter, is designed to upload files from /mnt/user-data. This is a dedicated directory used by Anthropic’s Claude artificial intelligence (AI) tool to process uploads and output […]

5 steps to manage shadow AI tools without degrading employee performance

When employees install an AI writing assistant, connect Coding CoPilot to their IDE, or start summarizing a meeting using a new browser tool, they’re doing exactly what productive employees should be doing: finding ways to work faster. In most organizations today, employees run three to five AI tools a day. Most were never reviewed by […]

GlassWorm malware removal disrupts developer supply chain attack infrastructure

Rabi LakshmananMay 27, 2026Malware/Threat Intelligence CrowdStrike announced that it is partnering with Google and the Shadowserver Foundation to simultaneously disrupt all command and control (C2) channels associated with GlassWorm, a persistent software chain campaign that targets software developers through malicious packages and extensions. “Since at least early 2025, GlassWorm operators have systematically targeted software developers, […]

Three SOC steps to shut down incident risk early

Most organizations still view cyber defense as a fortress issue. Build stronger walls, add guards, buy different detection engines. But modern incidents rarely break through the front gates. They drift around under the guise of routine activity, hide behind legitimate processes, and quietly accumulate risk long before anyone calls it an “incident.” This completely changes […]

Gitea vulnerability allows private container images to be exposed without authentication

Rabi LakshmananMay 27, 2026Vulnerabilities/Software Security Cybersecurity researchers have revealed a security flaw in Gitea, an open source self-hosted platform for version control. This flaw allows an unauthenticated, remote attacker to obtain private container images from a Gitea deployment without requiring an account, password, or other credentials. This vulnerability is tracked as CVE-2026-27771 (CVSS score: N/A) […]

AI chatbot recommendations redirect users to cryptojacking malware site

Microsoft has warned of an active cryptojacking campaign that uses artificial intelligence (AI) chatbot interactions as a mechanism to display malicious download sites. “This new delivery technology extends social engineering beyond traditional search results and increases the visibility of malicious software recommendations,” Microsoft Defender Experts and the Microsoft Defender Security Research Team said in a […]

MuddyWater uses DLL sideloading to spy on nine countries

The Iranian hacker group known as Muddywater is said to be behind a new campaign that will affect at least nine organizations in nine countries on four continents in the first quarter of 2026. According to Symantec and Carbon Black’s Threat Hunter Team, the activity targeted industrial and electronics manufacturing, education and public sector entities, […]

New AI DDoS attacks are getting smarter. Learn how to fight back with this webinar

hacker newsMay 26, 2026Web security/artificial intelligence Every day, hackers find new ways to crash websites and steal data. But now something has changed. Hackers no longer operate alone. They are now using powerful artificial intelligence (AI) tools to make their attacks faster, more powerful, and much harder to stop. According to a recent update on […]