North Korean Hackers Hide ‘Ted’ Backdoor Inside Trojanized HAProxy to Spy on South Korean Firms
Rapid7 researchers have uncovered a DPRK-linked Linux intrusion toolkit — built around a modified HAProxy binary dubbed Ted and a companion remote access tool called CurlRAT — that...
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent...
Fake ‘Lithium’ Minecraft Optimization Mod Hides Myth Stealer RAT Behind 12 Working Features
A trojanized Minecraft performance mod posing as the popular Lithium optimization project is quietly installing Myth Stealer, an information-stealing remote access tool that harvests browser credentials, session cookies,...
North Korea-Linked Hackers Hide OtterCookie Malware Inside 14 Fake Mac Apps
Researchers have identified fourteen trojanized macOS installers impersonating popular utilities like The Unarchiver and Sketch, all delivering the OtterCookie credential-stealing malware. The campaign, tied to North Korea's long-running...
Over 14,000 Dahua Cameras Compromised With Backdoors That Survive Factory Resets
Researchers at Hunt.io say a 35-day campaign compromised more than 14,000 internet-connected Dahua cameras, planting hidden administrator accounts and abusing cloud recovery codes that persist even through password...
Trezor Reveals Its ShipMonk Breach Was Far Bigger Than First Disclosed
Hardware wallet maker Trezor has confirmed that a breach at its fulfillment partner ShipMonk exposed far more customers than originally reported, after retained order data that should have...
Google Rushes Emergency Chrome Patch as Attackers Exploit V8 Zero-Day
Google has pushed an emergency Chrome update after confirming that a type confusion flaw in the V8 engine, tracked as CVE-2026-85046, is being actively exploited in the wild....
TP-Link Patches Archer AX55 Flaws Enabling Code Execution and Password Theft
TP-Link has fixed two Archer AX55 v4 vulnerabilities affecting EasyMesh and web login security. A local attacker could crash or potentially take over the router, while captured HTTP...