Stealer Spoofs Google, Microsoft & Apple, Then Backdoors macOS
The SHub Reaper stealer, which hides behind fake WeChat and Miro installers, marks a shift from ClickFix social engineering to Apple script-based execution.
Aggregated from vendor advisories, security research, and industry publications.
The SHub Reaper stealer, which hides behind fake WeChat and Miro installers, marks a shift from ClickFix social engineering to Apple script-based execution.
Not by name, but Laurie Anderson quotes me in one of the tracks of her new album: My favorite quote is from a cryptologist who said “If you think technology will solve your problem…
UK folk increasingly don't believe AI jobs revolution will end in prosperity for anyone outside the boardroom, say researchers
Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC. "The Drupal Security Team ur…
The 13-country effort, named Operation Ramz, targeted cyber threats in the Middle East and North Africa region. The post 201 Arrested in Crackdown on Cybercrime in Middle East, Nor…
Low-cost laser-guided rockets offer cheaper way to swat Shahed-style threats than firing pricey air-to-air missiles
Joule Studio 2.0 waves the flag of interoperability, API policy tells enterprises who's really in charge
AI interactive flat panel aimed at offices, elder care, and classrooms with built-in conferencing, automation, and monitoring features unveiled
Patched in April, the underlying vulnerability allows local attackers to elevate their privileges to root. The post PoC Released for DirtyDecrypt Linux Kernel Vulnerability appeare…
Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code…
You don't really want that entering your system, do you?
If you’ve sat through any vendor pitch in the last year, you’ve heard the promise. AI will detect the anomaly, correlate the signals, identify the root cause, maybe even remediate …
From campus ceremonies to Linux communities and academic journals, resistance to LLM evangelism is getting louder
Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extensio…
CFO says GPU rentals are ‘structurally higher margin than CPU cloud’
The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection. The post Critical Vulnerability Exposes Industrial Robot F…
In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sen…
Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the…
Threatens unspecified ‘fees’ and warns of economic consequences – yet only major kinetic action could stop data flows entirely
Supports Nvidia Grace and Ampere processors
While also spoofing all the trusted domains - Apple, Microsoft, and Google - in the same attack
AI will indeed eat the world – if your world involves software-size margins
More than 200 individuals were arrested for cybercrime activities during INTERPOL's Operation Ramz, which focused on the Middle East and North Africa. [...]
Plus three other stealers in three other packages, all from the same scumbag
Understanding AI BOMs and where they fit into risk management for artificial intelligence.
CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes.
A new variant of the 'SHub' macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. [...]
Even self-described ‘Trump in high heels’ candidate warns bit barns could send power bills soaring
The now-patched vulnerabilities in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence.
Chip startup NextSilicon's high-performance-computing-focused accelerators get Sandia National Lab's stamp of approval