SLEEPWALKER is a newly identified Windows backdoor built to wait rather than call home. Once placed on a compromised device, it can sit inactive for an extended period, only responding …
Hackers Hide RevStealer Inside Fake Claude Opus 5 App to Steal Passwords and Crypto
Hackers are using a fake Claude Opus 5 desktop application to distribute RevStealer, a Windows malware built to take passwords, browser data and cryptocurrency wallet material. The campaign turns demand …
Popular npm Package With 150K Weekly Downloads Compromised in Mini Shai-Hulud Supply-Chain Attack
A JavaScript development package has been caught in a supply-chain compromise that can run malicious code when installed. The incident affects a tool with about 150,000 weekly downloads, risking developer …
Hackers Use Malicious Website Themes to Steal Crypto Wallet Seeds From iPhones
Hackers are using booby-trapped website themes to turn visits from iPhone users into a route for spyware and cryptocurrency theft. The campaign hides harmful code inside themes used by Vietnamese …
Hackers Compromise Cisco Routers to Spy on Networks and Reach Critical Infrastructure
Fire Ant has moved beyond attacking individual systems and is now compromising network infrastructure that organizations trust to move traffic and manage access. The actor has turned Cisco IOS XR …
Hackers Target AWS Root Accounts at 150+ Organizations in Password-Spraying Campaign
Datadog Security Research observed a password-spraying campaign targeting AWS root accounts at more than 150 organizations between July 24 and August 23, 2026, with repeated failed console login attempts against …
Anthropic Hardens Claude Security After AI Models Gain Unauthorized Access to Real Systems
Anthropic has hardened security around its Claude models after several incidents in which the systems gained unauthorized access to real computers during cybersecurity evaluations. The company said the cases reflected …
BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update
Attackers hijacked BGP routing for Softaculous last week and delivered a malicious Virtualizor update to a handful of hypervisor servers, according to a vendor incident report. Hosting providers use Virtualizor …
Broadcom Launches VMware AI Factory to Secure Enterprise AI Agents
Broadcom unveiled VMware AI Factory at VMware Explore 2026 in Las Vegas, introducing a software-defined foundation within VMware Private AI Cloud designed to help enterprises deploy, govern, and secure AI …
Microsoft Investigating New Exchange Online Outage Tracked as EX1464935 [Updated]
Microsoft has opened an active investigation into a new Exchange Online disruption after a wave of user reports flagged access and mail-flow problems across the cloud-based email service. The incident, …
