GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms

Cybersecurity researchers have uncovered a sophisticated malware campaign that uses paid search ads and manipulated GitHub links to deliver malicious payloads, targeting Western European IT and software firms. The campaign employs advanced evasion techniques like encrypted payloads and GPU-based decryption routines, posing significant threats to organizations. #GPUGate #Malvertising…

Read More
Over 6,700 Private Repositories Made Public in Nx Supply Chain Attack

Cybercriminals exploited secrets stolen during the Nx supply chain attack to publicly release over 6,700 private repositories, leading to widespread data exposure. The attack involved malicious Nx package versions, AI CLI exploitation, and data exfiltration of sensitive credentials and files, impacting hundreds of users and organizations. #NxSupplyChain #s1ngularity #GitHubRepositories #AIExfiltration…

Read More
Subverting Code Integrity Checks to Locally Backdoor Signal, 1Password, Slack, and More

Electron CVE-2025-55305 is a framework-level bypass that allows attackers to backdoor Chromium-based applications by tampering with V8 heap snapshot files, enabling unsigned JavaScript to run despite integrity checks. Proofs of concept showed backdoors in Signal, 1Password (patched in v8.11.8-40), Slack, and Chrome derivatives by overwriting snapshots to clobber builtins like Array.isArray….

Read More
AI-powered malware hit 2,180 GitHub accounts in “s1ngularity” attack

The Nx “s1ngularity” supply chain attack led to the leak of thousands of account tokens and repository secrets, affecting millions of users and exposing sensitive data. The incident involved a malicious NPM package with post-install malware and advanced prompt tuning techniques employed by threat actors. #Nx #s1ngularity #GitHub #NPM #telemetry.js

Read More
Cybersecurity News | Daily Recap [05 Sep 2025]

Two major vulnerabilities and patch guidance dominated this recap, including active exploitation of SAP S/4HANA (CVE-2025-42957) and Sitecore (CVE-2025-53690) zero-days prompting rapid patching and monitoring. The report also covers notable APT activity, law enforcement actions, data breaches, and evolving malware campaigns affecting organizations and industries worldwide. #CVE-2025-42957 #CVE-2025-53690 #NotDoor #Kimsuky #GhostRedirector #PowerSchool #JLR #SalesforceDrift

Read More
Threat Actors Impersonate Microsoft Teams To Deliver Odyssey macOS Stealer Via Clickfix

Forcepoint and CloudSEK analysis identifies a clickfix campaign that impersonates Microsoft Teams to deliver the Odyssey AppleScript stealer, which harvests credentials, browser cookies, Apple Notes, and numerous desktop/extension cryptocurrency wallets before zipping and exfiltrating data to a C2. The malware establishes persistence via LaunchDaemons and replaces Ledger Live with a trojanized version to enable long-term access and financial theft. #Odyssey #LedgerLive

Read More
Dark Web Profile: GLOBAL Ransomware

GLOBAL Ransomware is a mid-2025 RaaS rebrand of earlier families like Mamona and BlackLock that offers multi-platform payloads, an AI negotiation chatbot, and unusually high affiliate revenue shares to rapidly scale operations. Its campaigns target high-impact sectors (notably healthcare) across the U.S., Europe, Australia and Brazil and use affiliate-supplied initial access, ChaCha20-Poly1305 encryption, and Tor-based leak/negotiation portals. #GLOBAL #BlackLock

Read More
An MDR Analysis of the AMOS Stealer Campaign Targeting macOS via ‘Cracked’ Apps

Trend Research analyzed an Atomic macOS Stealer (AMOS) campaign that lures macOS users with trojanized “cracked” apps and malicious copy‑paste Terminal commands to install a data‑stealer. The campaign uses rotating redirector domains and URL rotation to evade takedowns and exfiltrates stolen credentials, browser data, crypto wallets, Telegram data, keychain items, and…

Read More
Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms

North Korea-aligned actors behind the Contagious Interview cluster used cyber threat intelligence platforms (Validin, VirusTotal, Maltrail) and coordinated team workflows (likely Slack) to monitor, scout, and rapidly replace exposed infrastructure while conducting ClickFix social engineering against job seekers in the crypto sector. SentinelLABS recovered ContagiousDrop server logs showing over 230 victims and numerous IOCs including domains, IPs, email addresses, and SHA-1 hashes. #ContagiousInterview #ClickFix

Read More
Lazarus Targets DeFi with Layered RAT Campaign

A Lazarus subgroup targeting financial and cryptocurrency organizations used social engineering and likely a Chrome zero-day to deploy multiple RATs — PondRAT, ThemeForestRAT and RemotePE — progressing from initial loaders to a more advanced in-memory RAT. The actor used phantom DLL persistence via PerfhLoader, extensive discovery tools, and cleaned up artifacts before deploying RemotePE, linking activity to AppleJeus, POOLRAT, Citrine Sleet and Gleaming Pisces. #PondRAT #ThemeForestRAT

Read More