Ravie LakshmananSep 14, 2026Malware / Browser Security A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly […]
Category: Malicious
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration […]
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run […]
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript […]
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the […]
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Ravie LakshmananAug 20, 2026Browser Security / Cryptocurrency A set of 40 Mozilla Firefox extensions has been found to engage in […]
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud […]
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker’s choosing. On the […]
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Swati KhandelwalAug 11, 2026AI Security / Cyber Attack A malicious tool server connected to an AI coding assistant can quietly […]
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a […]
