ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

A new breed of macOS malware, known as ClickFix, has emerged, targeting cryptocurrency wallets and draining funds from unsuspecting users. The attacks are noteworthy for their sophistication, leveraging a combination of social engineering and clever coding to evade detection. ClickFix operates by masquerading as a legitimate software update, tricking victims into installing the malicious payload. … Read more

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A massive wave of malicious packages has hit the popular npm package repository, with nearly 800 compromised modules delivering a potent combination of a cross-platform Remote Access Trojan (RAT) and an infostealer. This alarming incident underscores the importance of security in software development and highlights the need for developers to remain vigilant against supply chain … Read more

North Carolina Ports confirms cyberattack disrupting operations

A devastating cyberattack has crippled operations at three key North Carolina ports, leaving shippers and truckers scrambling to adjust to the disruption. The North Carolina Ports Authority confirmed that a cyberattack on August 4th targeted IT systems at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, causing a widespread … Read more

Unlimited Technology Systems breach impacts 3.8 million people

A massive healthcare software company has revealed a data breach that compromised the sensitive information of nearly 4 million people. Unlimited Technology Systems, which provides financial and revenue cycle technology for specialty healthcare providers, reported that hackers gained access to its server in October 2025 and stole personal details, including social security numbers, medical records, … Read more

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A New Wave of Vishing Attacks Exploits Personal Phones to Steal SaaS Data, Leaving Millions Exposed A sophisticated wave of vishing (voice phishing) attacks has been targeting individuals’ personal phones, aiming to steal sensitive data from Software as a Service (SaaS) applications. According to reports, the UNC6671 threat actor group is behind these campaigns, which … Read more

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

A New Type of macOS Malware, ClickFix Attacks, Steals Cryptocurrency Wallets and Personal Data ClickFix attacks have emerged as a new threat in the cybersecurity landscape, specifically targeting macOS users. These sophisticated cyberattacks involve the use of malware that can drain cryptocurrency wallets and steal sensitive personal data. The malicious software is designed to evade … Read more

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A recent investigation has uncovered a disturbing trend in the world of open-source software, where nearly 800 malicious packages have been discovered on npm (Node Package Manager), a popular repository for JavaScript libraries. These compromised packages deliver a cross-platform Remote Access Tool (RAT) and an Infostealer malware to unsuspecting developers and their organizations. The affected … Read more

AI-Generated Patches Fail Half the Time

As AI-generated code continues to revolutionize software development, a growing concern is emerging about its reliability when it comes to patching security vulnerabilities. A recent study by identity management firm 1Password found that even the latest AI systems are only effective at generating patches about half the time, introducing new bugs and weaknesses in the … Read more

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

A New Spectre Variant Bypasses Recent Fixes, Leaks Linux Password Hashes A team of researchers from MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) has discovered a novel way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks. The method, dubbed TONTOU, exploits a previously unknown vulnerability in modern processors’ indirect branch predictors, … Read more

North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has been hit by a cyberattack that disrupted IT systems and slowed operations at several key facilities. The attack affected the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, all major commercial deepwater seaports and an inland hub. According to reports, the attack was detected … Read more