DOUBLECUP Hides a ClickFix Payload in the Browser Cache
The service preloads a payload-bearing PNG, copies a browser-specific command, and keys the final in-memory stage to the victim's public IP address.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
The service preloads a payload-bearing PNG, copies a browser-specific command, and keys the final in-memory stage to the victim's public IP address.
Read article →A compromised maintainer account published Keyv-family packages with valid provenance, an install-time credential stealer, and code that could poison more npm releases.
Read article →Gitea 1.22.1 through 1.27.0 can let an anonymous request read files as the service account, expose the internal token, and plant a Git hook that executes during a clone.
Read article →INC ransomware activity requires SMA 1000 operators to investigate logs and configuration as well as apply the hotfix.
Read article →An integration error routed wallet entropy through MicroPython's deterministic Yasmarang fallback. Updating prevents new weak seeds, but existing ones still require migration.
Read article →A compromised Adform tracking file used browser events, DOM observers and form-field hooks to keep substituting Bitcoin, Ethereum and Tron addresses.
Read article →A ServiceWorker and SharedWorker combine a clean Bun runtime, delivered PE sections, and locally generated bytes before a same-origin download.
Read article →A poisoned build can start a memory-resident loader, re-arm through macOS preferences, and seed more projects, Git hooks, and archives.
Read article →A crafted AD CS chase sent the CA to rogue directory services. July updates add a real-DC check, but defenders still need issuance and replication evidence.
Read article →IPMI's RAKP exchange exposes material for offline password cracking, leaving defenders with a management-plane incident that host telemetry may miss.
Read article →One variant uses UPnP to open 155 inbound paths, then relays same-port traffic through infected devices that conceal the real command servers.
Read article →Actors changed controller IP addresses and passwords across at least seven states. Operators need to compare running logic with a trusted baseline and investigate activity on connected devices.
Read article →On-premises VCO is exposed by default. Arista says defenders must inspect web activity and managed Edge state after patching.
Read article →