DPRK-linked actors use GitHub C2 and LNK phishing in South Korea, enabling persistent PowerShell control and data ...
UAT-10362 spear-phishing targets Taiwanese NGOs in October 2025, deploying LucidRook malware for data exfiltration and ...
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
A series of malicious LNK files targeting users in South Korea has been detected using a multi-stage attack chain that uses ...
The massive amount of junk code that hides the malware's logic from security scans was almost certainly generated by AI, ...
Windows 11 KB5086672 is now rolling out as an optional update with several notable improvements after March 2026 update ...
Microsoft has deprecated and removed the Support and Recovery Assistant (SaRA) command-line utility from all in-support ...
A North Korea-nexus threat actor compromised the widely used axios npm package, delivering a cross-platform remote access ...
Fake CAPTCHA pages can install the StealC infostealer. Don't paste or run commands; disconnect and change passwords.
The widely used Axios HTTP client library, a JavaScript component used by developers, was recently hacked to distribute ...