Trust as the Attack Surface: Inside the ClickFix Campaigns Powering ACR Stealer- 258
July 19, 2026
No vulnerability was patched, no exploit chain engineered, in the campaigns Microsoft disclosed distributing ACR Stealer through
North Korea just made its malware payload host itself on the blockchain- 252
July 5, 2026
North Korean threat actors behind the long-running Contagious Interview campaign have distributed more than 100 malicious
The worm that infects the tools developers trust to catch it- 246
April 30, 2026
TeamPCP's Mini Shai-Hulud campaign has spent the past 48 hours poisoning official npm and
The Worm in the Toolchain: How TeamPCP Built a Credential Extraction Economy Inside Open Source- 201
June 23, 2026
The most consequential credential theft does not happen when a user clicks a phishing link. It happens
Gootloader malware back for the attack, serves up ransomware- 97
November 6, 2025
The resurgence of Gootloader malware illustrates the evolution of cyber threats where established tactics like SEO poisoning