Category: Exploits
Coldcard Maker Destroys Vulnerable Inventory After $88M Bitcoin Theft
Coinkite has scrapped remaining stock of its Coldcard hardware wallets after attackers exploited a years-old firmware flaw to drain more than $88…
Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy
A supply-chain compromise of Adform's widely embedded tracking script let attackers silently replace Bitcoin, Ethereum, and TRON addresses copied by site visitors,…
Hijacked Hotel Wi-Fi Delivers CornFlake Spyware via Fake Browser Updates
Microsoft says a Storm-2945 campaign dubbed CaptiveCrunch is hijacking hotel Wi-Fi captive portals to push fake browser updates that install the CornFlake…
Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy
Attackers tampered with a JavaScript file served by ad-tech firm Adform, turning it into a browser-based tool that silently rewrote copied cryptocurrency…
Arch Linux Halts AUR Package Adoption After Malware Takeover Surge
Arch Linux has temporarily disabled Arch User Repository package adoption following a wave of malicious takeovers, with researchers linking the campaign to…
Dysphoria Botnet Grows to 200,000 Devices Using Blockchain-Based C2
Researchers at QiAnXin XLab have tracked a rapidly evolving DDoS botnet called Dysphoria that hides its command infrastructure inside Ethereum and Solana…
GitLab RCE PoC Released: Authenticated Users Can Run Commands as Git
A researcher has published working exploit code for a GitLab vulnerability patched six weeks ago, showing how any authenticated user with push…
Hackers Hijack Hotel and Conference Wi-Fi to Steal Microsoft 365 Logins
A DNS hijacking campaign targeting Wi-Fi gateways at hotels and conference centers is redirecting traveling employees to fake Microsoft 365 login pages,…
Upbound Discloses Data Theft Behind $13M in Fraudulent Acima Leases
The fintech parent of Rent-A-Center and Acima told the SEC that attackers used stolen customer data to obtain goods through fraudulent lease-to-own…
Microsoft Flags Surge in ACR Stealer Attacks Using ClickFix and WebDAV Tricks
Microsoft says attackers ramped up ACR Stealer campaigns between late April and mid-June, using ClickFix social engineering, WebDAV shares, and MSHTA to…
Abbott Investigates Two Separate Breaches Amid ShinyHunters Extortion Threat
Abbott Laboratories is probing unauthorized access to legacy Exact Sciences systems claimed by ShinyHunters, plus a second alleged breach of its LabCentral…
North Korean Hackers Hide OtterCookie Malware Inside SVG Flag Images
The Contagious Interview campaign is using steganography in SVG files to sneak a four-stage payload past victims lured by fake job postings…