Trivy Supply Chain Attack Distributes Infostealer and Wiper Malware

A recent supply chain attack on Trivy has led to the distribution of malicious Docker images, impacting developer environments and exposing sensitive data.

A recent supply chain attack on Trivy has led to the distribution of malicious Docker images, impacting developer environments and exposing sensitive data.

Microsoft has reported a significant phishing campaign exploiting the U.S. tax season, affecting approximately 29,000 users across various industries.

A new malware named Speagle has been identified, which hijacks the Cobra DocGuard software to extract sensitive data from infected systems.

A malicious npm package posing as an OpenClaw installer has been identified, capable of deploying a remote access trojan (RAT) and stealing sensitive data from macOS systems.

A new multi-stage malware campaign, dubbed VOID#GEIST, has been identified, utilizing batch scripts to deliver various remote access trojans, including XWorm, AsyncRAT, and Xeno RAT.

The hacking group Transparent Tribe has adopted AI tools to enhance its malware production, primarily targeting Indian government entities and private businesses.

Fake installers for the AI agent OpenClaw have emerged, delivering malware to unsuspecting users searching on Bing.

Microsoft has issued a warning regarding ongoing OAuth abuse scams that exploit phishing tactics to deliver malware, particularly targeting government and public-sector organizations.

Security researchers have identified a new backdoor malware, Dohdoor, linked to suspected North Korean cyber intruders targeting US educational and healthcare institutions since December.

The Steaelite remote access trojan combines data theft and ransomware capabilities, streamlining double extortion attacks on Windows systems.