
A global malware campaign is leveraging compromised WhatsApp accounts to distribute malicious VBScript files disguised as financial documents. Attackers target users of WhatsApp Desktop and WhatsApp Web, sending attachments like "Financial Reports.vbs" to the…

Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software. Per findings from Kaspersky, the active campaign is tar…

This week in cybersecurity saw a surge of World Cup-related scams, malware hidden in gaming tools, a fake breach-reporting incident that briefly disrupted a state portal, and more. The World Cup is here, which is great news for fans (and my social media feeds…

Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions we deprive cyberc…

Researchers found malicious Wallpaper Engine downloads on Steam Workshop distributing infostealers, backdoors, and account-hijacking malware.

This week in cybersecurity saw a surge of World Cup-related scams, malware hidden in gaming tools, a fake breach-reporting incident that briefly disrupted a state portal, and more. The World Cup is here, which is great news for fans (and my social media feeds…

Attackers have spent the past several months smuggling malware into Steam through animated desktop wallpapers.
GitHub has confirmed a cyberattack after a threat actor claimed to have stolen and listed company data for sale. The breach involved unauthorised access to internal repositories via a "poisoned" VS Code extension, with the attacker's claims of accessing nearl…

Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver malicious code and conduct ransomware and other attacks, compromising thousands of machines and networks a…

Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) that allowed attackers to sign malware with fake trusted certificates. Microsoft said it disrupted a cybercrime operation run by a threat actor named Fox Tempest, which helped threat acto…

Fox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other cybercriminals, including Vanilla Tempest and Storm groups, to more effectively distribute malicious code, including ransomware. The post Exposi…

The downstream impact of that service’s operations “has resulted in attacks against a broad range of industry sectors” in the U.S. and other nations, the company said.

The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as Internet of Things (IoT) devices, during Q1 2026.

A new malware-as-a-service threat is targeting hundreds of banks around the world by giving cybercriminals tools to steal credentials and take over accounts. According to a new advisory from the cybersecurity firm iZOO Logic, the threat was identified as a Te…
Cybersecurity firm Kaspersky has warned Indian consumers about a sophisticated phishing campaign by the SilverFox hacker group. These malicious emails, disguised as official Income Tax Department notices, aim to trick users into downloading malware. The attac…