Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

26/06/2026 0 Comments 0 tags

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

26/06/2026 0 Comments 0 tags

An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig

Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales Cutoff

26/06/2026 0 Comments 0 tags

Russian authorities used Cellebrite’s UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling

Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

26/06/2026 0 Comments 0 tags

The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine,

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

25/06/2026 0 Comments 0 tags

An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

25/06/2026 0 Comments 0 tags

It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working,

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

25/06/2026 0 Comments 0 tags

A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst’s artificial intelligence (AI) tools and trick

Surviving the Mythos Era: Richard Bejtlich on the Case for NDR

25/06/2026 0 Comments 0 tags

Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How

New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns

25/06/2026 0 Comments 0 tags

A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

25/06/2026 0 Comments 0 tags

An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new