Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Grandoreiro returns, Swiss prosecutors sought a 12-year sentence for ransomware developer, a Medusa ransomware warning, ...
Ansible.Debugger is a PowerShell module that enables interactive debugging of PowerShell-based Ansible modules using Visual Studio Code. It works in conjunction with the ansible-test pwsh-debug ...
Hotel Wi-Fi malware campaign CaptiveCrunch, attributed to Russia's SVR-linked Midnight Blizzard, compromised hotel captive portal gateways since May 2026 to deliver CornFlake spyware and steal ...
North Korea-linked threat actor Kimsuky has been observed targeting organizations in South Korea and Japan with ...
Kimsuky uses phishing and a malicious Chrome extension to steal Gmail messages, attachments, and control infected computers.
Cybersecurity researchers have uncovered wider use of PavinLoader, a multi-stage malware loader linked to ClickFix lures, ...
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its ...
The implant ensures defenders only see legit Microsoft services rather than unknown external domains, making it more ...
This week’s cybersecurity recap covers AI agents breaching Hugging Face, Chinese spy proxies, router backdoors, PaperCut ...
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other ...
Windows Latest found hidden strings inside the Link to Windows app revealing remote shutdown, restart, and sleep controls for ...