Serverless Phishing Kit on GitHub Targets Mexican Banks
GitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentials
20 articles
GitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentials
Key Points Introduction In this research, we analyze a clipboard hijacker campaign that is hidden inside a collection of “solutions” and “tools” that claim t...
SANS Institute study finds few SOCs have built AI into defined workflows, despite widespread adoption
Rokarolla Android trojan steals banking logins and spies on victims while blocking fraud alerts
The FBI claims couriers are being used to circumvent bank transfers in crypto investment schemes
Domain of dark web money laundering platform AudiA6 seized and suspects arrested in joint operation by the FBI, Europol and others
MaaS trojan SilabRAT uses HVNC and browser cloning to hijack sessions and steal crypto
North Korean actor UNK_DeadDrop targeted developers with fake coding tasks to steal crypto
Lloyds Banking Group shared its approach for securing agentic AI workflows, with a mix of hands on experimentation and cross functional governance
Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.
New actor Jinx-0164 hit crypto developers with fake recruiter lures and macOS malware
The infostealer payload in this campaign collect a vast amount of data, from collaboration authentication keys to cryptocurrency wallets
Elastic Security Labs presents a detailed reverse-engineering analysis of PHANTOMPULSE, the long-lived RAT delivered to crypto-sector victims through the REF...
Elastic Security Labs presents a detailed reverse-engineering analysis of PHANTOMPULSE, the long-lived RAT delivered to crypto-sector victims through the REF...
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven mil...
Learn how the "Harvest Now, Decrypt Later" (HNDL) risk exposes long-lived sensitive data today, regardless of when Cryptographically Relevant Quantum Compute...
REF3076 uses a trojanized Logitech installer to deploy TCLBANKER, a Brazilian banking trojan with environment-gated payloads, WPF fraud overlays, and self-pr...
REF3076 uses a trojanized Logitech installer to deploy TCLBANKER, a Brazilian banking trojan with environment-gated payloads, WPF fraud overlays, and self-pr...
Explore the 2026 Claude Mythos breach, supply chain risks, and the $2B+ crypto theft pipeline.