Brewing Trouble: Homebrew Spoofed Sites on the Rise

Attackers created multiple spoofed Homebrew installer sites that copied brew.sh but forced users to use a page Copy button which injects a hidden malicious shell command into the clipboard, leading to parallel download and execution of payloads like Odyssey Stealer. Kandji observed the infrastructure, Russian-language code comments suggesting payload-as-a-service and exfiltration to Telegram, and listed domains and a malicious curl command used in the campaign. #OdysseyStealer #HomebrewOnline

Read More
Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks

Cybersecurity researchers have uncovered a campaign targeting WordPress sites with malicious JavaScript injections leading to site redirection and malware distribution. The campaign uses sophisticated techniques like remote payload loading and cache smuggling to evade detection and deliver malicious content, emphasizing the importance of securing WordPress environments and implementing strong security measures….

Read More
The ClickFix Factory: First Exposure of IUAM ClickFix Generator

Attackers are commoditizing the ClickFix social-engineering technique into phishing kits like the IUAM ClickFix Generator to automate creation of spoofed browser-verification pages that trick victims into manually executing malware. Observed campaigns delivered DeerStealer and Odyssey infostealer using clipboard-injection and OS-detection features from hosted phishing pages. #IUAM_ClickFix_Generator #DeerStealer #Odyssey…

Read More
Microsoft and Steam Take Action as Unity Vulnerability Puts Games at Risk

A critical vulnerability (CVE-2025-59489) in Unity allows attackers to execute arbitrary code via malicious command-line arguments, mainly impacting applications supporting debugging features. Updates released by Unity, Microsoft, and Valve aim to mitigate the risk, but the threat poses significant concerns for affected systems. #UnityCVE #UnityPlayerDll…

Read More
Privacy Protection: Encrypted DNS

Encrypted DNS enhances online privacy by encrypting DNS queries using protocols like DoH, DoT, and others, preventing third parties from monitoring or manipulating internet traffic. Popular providers such as NextDNS, Cloudflare DNS, and AdGuard DNS offer secure, customizable, and privacy-focused DNS services that help protect users from threats and censorship. #NextDNS #CloudflareDNS #AdGuardDNS

Read More
Google Drive for desktop gets AI-powered ransomware detection

Google has introduced an AI-powered security feature for Google Drive that detects and pauses file syncing during ransomware attacks, protecting stored documents. This innovative tool leverages AI trained on real-world ransomware samples and is available to many Google Workspace users, enhancing backup recovery and threat response. #GoogleDrive #RansomwareDetection

Read More
Apple Security Update Addresses Critical Font Parser Vulnerability Across Multiple Platforms

Apple has released security updates across iOS, macOS, and other platforms to fix a critical font parser vulnerability (CVE-2025-43400). These patches address a flaw that could allow malicious fonts to cause memory corruption or remote code execution, emphasizing the importance of timely updates. #CVE-2025-43400 #AppleSecurityUpdate…

Read More
Cross-Examining the CAPTCHAgeddon Brought on by ClickFix

Guardio uncovered ClickFix, a browser-based stealer that used fake CAPTCHA pages to trick users into executing a malicious PowerShell command and exfiltrate credentials, and published 172 IoCs including 156 domains and 16 IPs. WhoisXML API’s analysis expanded those IoCs—finding thousands of related domains, IPs, registrant- and email-linked domains, and early warnings for 30 domains—and linked broad DNS and WHOIS artifacts to the campaign. #ClickFix #Guardio

Read More