North Korea-Linked Hackers Hide OtterCookie Malware Inside 14 Fake Mac Apps
Researchers have identified fourteen trojanized macOS installers impersonating popular utilities like The Unarchiver and Sketch, all delivering the OtterCookie credential-stealing malware. The campaign, tied to North Korea's long-running...
Over 14,000 Dahua Cameras Compromised With Backdoors That Survive Factory Resets
Researchers at Hunt.io say a 35-day campaign compromised more than 14,000 internet-connected Dahua cameras, planting hidden administrator accounts and abusing cloud recovery codes that persist even through password...
Trezor Reveals Its ShipMonk Breach Was Far Bigger Than First Disclosed
Hardware wallet maker Trezor has confirmed that a breach at its fulfillment partner ShipMonk exposed far more customers than originally reported, after retained order data that should have...
Google Rushes Emergency Chrome Patch as Attackers Exploit V8 Zero-Day
Google has pushed an emergency Chrome update after confirming that a type confusion flaw in the V8 engine, tracked as CVE-2026-85046, is being actively exploited in the wild....
TP-Link Patches Archer AX55 Flaws Enabling Code Execution and Password Theft
TP-Link has fixed two Archer AX55 v4 vulnerabilities affecting EasyMesh and web login security. A local attacker could crash or potentially take over the router, while captured HTTP...
NodeStealer Adds Keylogging and Screenshots to Its Account-Theft Arsenal
A new NodeStealer variant adds continuous keylogging, clipboard monitoring and screenshots to its browser and Facebook data theft. Financial services were the most affected sector in recent activity...
Toy Ghouls Hide New Windows Backdoors Behind MQTT and Matrix Traffic
The Toy Ghouls group has deployed two custom Windows backdoors that use MQTT and Matrix-based services for command traffic. The malware adds durable remote control to compromises previously...
AI-Orchestrated Intrusions Hit Asian Government and Political Networks
Attackers used an AI-orchestration framework alongside conventional exploits, stolen credentials and custom malware in a campaign spanning Asian government, political and education targets. The case shows how agentic...