
39 New Methods That Compromise Passkey Authentication
Researchers have identified 39 methods to compromise passkey authentication, exposing vulnerabilities in the infrastructure and user interfaces involved.
Stories tagged “Malware.”
30 stories

Researchers have identified 39 methods to compromise passkey authentication, exposing vulnerabilities in the infrastructure and user interfaces involved.

CrowdStrike released a zero-day exploit named 'FalconFlank' that allows attackers to escalate privileges on up-to-date Windows systems.

Coder's Cloudflare infrastructure compromised, delivering malicious Terraform modules containing credential-stealing code.

Cybersecurity researchers have disclosed details of a sophisticated malware framework called BraZetsu that turns compromised systems into valuable assets for criminal markets.

RMM phishing campaign targeting US, 45% of activity

US officials and CrowdStrike disrupt malware that redirected $150,000 in crypto over 8 years.

Malware campaign uses fake websites to distribute malicious software, compromising multiple organizations and industries in China.

Microsoft Defender for Office 365 mistakenly flags legitimate Google search links as malicious, causing warnings and alerts.

Russian hacker extradited from Cyprus faces charges for a 2016-2017 campaign using fake accounts to send malware-laced Excel attachments to thousands of users.

US federal grand jury indicted a Russian national for infecting thousands of freelancers with malware. Aktulaev was extradited from Cyprus and faces federal court in California.

International law enforcement agencies and private partners have taken down Sality malware infrastructure in a joint operation.

A Russia-aligned group, UAC-0099, is using a new technique called GuardBreaker to trick AI security tools by embedding dangerous prompts into malware.

Microsoft alerts about a new variant of ClickFix attacks that use fake Cloudflare CAPTCHA prompts to trick users into executing malicious PowerShell commands in Windows Terminal. The attacks lead to a multi-stage intrusion chain resulting in a reverse tunnel into the vict…

Anthropic alerts users that malware is stealing Claude login sessions, leading to unauthorized usage and account access.

Multiple Chrome and Edge extensions delivered malware framework to steal crypto, data, and inject malicious scripts. Google removed the extension from its marketplace.

Microsoft details new TerminalFix campaign targeting organizations with fake Cloudflare CAPTCHAs to deploy malicious PowerShell commands.

Researchers discover 19 Chrome and 1 Edge extension with malicious capabilities since 2024.

A Russian state-sponsored hacking group, APT28 (Fancy Bear), has deployed a new backdoor named HOOKEDGE, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. This sophisticated malware, an evolution of HEADLACE, uses macro-enabled Word documen…

Two men charged in Australia for alleged role in TeamPCP cybercrime group, which compromised open-source security scanners and AI gateway.

Independent malware researcher documents a new Windows backdoor called SLEEPWALKER that waits for a specific packet before executing commands written in its own bytecode.

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites.

A security firm has linked 77 Firefox extension identities to a campaign called the Offside Wallet Theft Factory, confirming 40 as malicious. These extensions impersonate popular crypto wallets, capturing recovery phrases through fake interfaces or modified code.

Seqrite Labs documents Operation QUICSILVER, a China-nexus cyber espionage campaign using Burmese-language graduation ceremony lures to deliver a Go-based QUICAgent backdoor against Myanmar's government and IT sectors.

A Chinese-speaking cybercrime group dubbed UAT-10147 has been targeting Windows and Linux web servers globally, using AI-powered tools to scale server attacks and deploy malware for SEO fraud and data theft.

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. It now requests VPN service permissions to create a local interface that allows it to control network traff…

Hackers use legitimate app to spread malware targeting Android car head units. Kaspersky notes first documented case of malware specifically for car head units.

Cybersecurity researchers found 14 trojanized npm packages that deliver an AI-powered Linux backdoor called RedC2 4.0.

Malware family SynkLoader being distributed via fake lock screen in Microsoft Teams phishing campaigns to steal credentials.

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. The end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.

Threat actors are using FTP server banners to hide commands that deliver two previously undocumented remote access trojans (RATs). Researchers found this technique has been in use since early July and remains operational.