ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

A New Type of macOS Malware, ClickFix Attacks, Steals Cryptocurrency Wallets and Personal Data ClickFix attacks have emerged as a new threat in the cybersecurity landscape, specifically targeting macOS users. These sophisticated cyberattacks involve the use of malware that can drain cryptocurrency wallets and steal sensitive personal data. The malicious software is designed to evade … Read more

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A recent investigation has uncovered a disturbing trend in the world of open-source software, where nearly 800 malicious packages have been discovered on npm (Node Package Manager), a popular repository for JavaScript libraries. These compromised packages deliver a cross-platform Remote Access Tool (RAT) and an Infostealer malware to unsuspecting developers and their organizations. The affected … Read more

AI-Generated Patches Fail Half the Time

As AI-generated code continues to revolutionize software development, a growing concern is emerging about its reliability when it comes to patching security vulnerabilities. A recent study by identity management firm 1Password found that even the latest AI systems are only effective at generating patches about half the time, introducing new bugs and weaknesses in the … Read more

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

A New Spectre Variant Bypasses Recent Fixes, Leaks Linux Password Hashes A team of researchers from MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) has discovered a novel way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks. The method, dubbed TONTOU, exploits a previously unknown vulnerability in modern processors’ indirect branch predictors, … Read more

North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has been hit by a cyberattack that disrupted IT systems and slowed operations at several key facilities. The attack affected the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, all major commercial deepwater seaports and an inland hub. According to reports, the attack was detected … Read more

Real emails, hijacked payments: Two H1 2026 attack chains

Cyberattacks Get More Sophisticated as Hackers Use Legitimate Accounts to Steal Payments In a disturbing trend that highlights the evolving tactics of cyber attackers, two recent campaigns have shown how hackers are using legitimate accounts and exploiting browser settings to steal payments from unsuspecting victims. The attacks, which were identified by Gen Threat Labs, used … Read more

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co., the iconic clothing giant behind the famous 501-line jeans, has fallen victim to a sophisticated cyberattack. Hackers used social engineering tactics to trick three of the company’s employees into giving them access to corporate data stored on their machines. The attack, which was detected recently by Levi’s security team, allowed the … Read more

Real emails, hijacked payments: Two H1 2026 attack chains

Cyber Attackers Evade Detection with Sophisticated Techniques in H1 2026 Cybersecurity experts have been tracking two complex attack chains that emerged during the first half of 2026, highlighting the evolving tactics used by attackers to evade detection and steal sensitive information. These campaigns demonstrate how cybercriminals are adapting their methods to bypass traditional security measures … Read more

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co. has recently disclosed a cyberattack that compromised corporate data stored on company-issued computers. The attackers used social engineering tactics to trick three employees into revealing sensitive information, which was then used to gain unauthorized access to the systems. The incident highlights the ongoing threat posed by social engineering attacks, where hackers … Read more

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A Critical GitHub Flaw Exposes Developers’ Secret CI Workflow Keys Developers working on a wide range of projects, from open-source software to proprietary applications, have been left exposed after a critical vulnerability was discovered in the way GitHub handles sensitive information in its Continuous Integration (CI) workflows. The flaw, found in the Gemini CLI and … Read more