Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SOC Prime
socprime.com > active-threats > new-gomir-variant-used-in-kimsuky-attack-on-south-korean-groupware-vendor

Kimsuky Targets South Korean Groupware with Gomir

2+ day, 21+ hour ago   (191+ words) SOC Prime Bias: Critical ENKI WhiteHat analyzed the campaign across 2025 and early 2026 and identified several malware strains developed in Go. The investigation showed how Kimsuky combined remote code execution on mail servers with social engineering to secure initial access. Analysts…...

@BleepinComputer
bleepingcomputer.com > news > security > fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware > amp

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

4+ day, 8+ hour ago   (562+ words) A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. Over 800 repositories pretended to be AI skills or MCP servers and appeared more than 600 times in public AI registries…...

@KnowBe4
blog.knowbe4.com > cyberheistnews-vol-16-29-clickfix-social-engineering-is-now-the-leading-malware-delivery-method

CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method

4+ day, 12+ hour ago   (1646+ words) ClickFix Social Engineering is Now the Leading Malware Delivery Method The ClickFix social engineering technique is now the top malware delivery method, according to a new report from ReliaQuest. These attacks trick users into copying a malicious command, then pasting…...

Google News
me.pcmag.com > en > security > 37701 > free-archive-program-7-zip-can-be-hacked-with-a-malicious-file

7-Zip Flaw Lets Malicious Files Run Malware

5+ day, 2+ hour ago   (239+ words) If you use 7-Zip, it’s time to patch. The free file-archiving program on Windows can be exploited to launch malware if it encounters a secretly booby-trapped file or website. An advisory about the software vulnerability was posted last week, warning…...

The Hacker News
thehackernews.com > 2026 > 07 > fakegit-campaign-uses-7600-github.html

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

5+ day, 7+ hour ago   (676+ words) Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed…...

SECURITY.COM
security.com > blog-post > three-ways-defend-against-lotl-attacks-now

3 Ways to Defend Against LOTL Attacks Now

5+ day, 16+ hour ago   (629+ words) Attackers are practical. If they can borrow your tools, why bring their own? A signed binary, A remote management utility. A script interpreter doing exactly what it was installed to do. None of it looks inherently hostile. That’s what continues…...

Cyber Security News
cybersecuritynews.com > clickfix-campaign-delivers-telepuz

ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

5+ day, 16+ hour ago   (481+ words) A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves. The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that can receive dozens of instructions from its operators. The attack begins with…...

Cybersecurity Dive
cybersecuritydive.com > spons > your-attack-surface-is-bigger-than-you-think > 825160

Your attack surface is bigger than you think

5+ day, 20+ hour ago   (453+ words) Arctic Wolf’s 2026 State of the Cybersecurity Attack Surface Report analyzes aggregated, anonymized data from more than 800,000 IT assets monitored through Aurora® Exposure Management. The findings reveal a common challenge across organizations of all sizes: fundamental security controls and asset visibility…...

SC Media
scworld.com > brief > new-telepuz-malware-spreads-via-clickfix-lures

New TELEPUZ malware spreads via ClickFix lures

1+ week, 2+ day ago   (57+ words) SC Media New TELEPUZ malware spreads via ClickFix lures OkoBot malware targets hardware wallet users with recovery phrase phishing MacOS ‘CrashStealer’ malware poses as crash reporter to steal credentials New Rust-based RAT named LabubaRAT impersonates NVIDIA software Get daily email…...

Infosecurity Magazine
infosecurity-magazine.com-magazine.com

Phishing Campaign Hides Lua Loader as TrueType Font File

1+ week, 2+ day ago   (482+ words) A large-scale phishing operation has been observed disguising a malicious script as a TrueType font file (.tff). Using the fake.ttf extension, a Lua-based loader is slipped onto Windows systems and a rotating cast of remote access trojans and infostealers…...