
The Trojan Horse in Your Browser
Browser extension security risks are rising due to supply chain attacks. Learn how trusted extensions turn malicious and how to protect your browser effectively.
Read more: The Trojan Horse in Your Browser
Browser extension security risks are rising due to supply chain attacks. Learn how trusted extensions turn malicious and how to protect your browser effectively.
Read more: The Trojan Horse in Your Browser
UAC-0099 is hijacking trusted apps like Notepad++ and WinRAR through malicious plugins and DLL sideloading. Here's the full infection chain, based on CERT-UA's technical advisory.
Read more: UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware
Days after the Coldcard entropy vulnerability went public, a phishing campaign impersonating Coinkite began tricking users into installing remote access malware disguised as a hardware audit tool.
Read more: From Exploit to Phishing: How Attackers Weaponized the Coldcard Entropy Incident
Gift card and crypto scams work because attackers borrow someone else's identity: a celebrity, an investment manager, even a loved one's voice. Here's how the impersonation angle actually plays out.
Read more: How Impersonation Fuels Gift Card and Crypto Scams
A malicious Google Ad leads to a real chatgpt.com link, where a fake "Codex" install command hides a base64 payload that drops the MacSync infostealer. Here's the full chain.
Read more: How a Real ChatGPT Link Delivers Phishing via a Fake Codex Install
Scam-style extortion is rising: attackers post fake data breach claims on leak sites with no real intrusion. Here's how the bluff works and how to verify before you panic.
Read more: Fake Data Breach Claims: Why Scam-Style Extortion Is Surging in 2026
The Vatican's Click to Pray app leaked the personal data of 700,000 users for over six months through a basic IDOR flaw. Here's how sequential user IDs and zero auth checks did the damage.
Read more: Click to Pray Exposes 700k Users: Inside a Textbook IDOR Failure