Attacks deploying the newly emergent Python-based Infiniti Stealer malware have been aimed at macOS devices as part of a new ClickFix campaign, reports SecurityWeek.
Threat actors have leveraged bogus VS Code security alerts to compromise GitHub developers with malware as part of a large-scale scam operation, according to BleepingComputer.
The Shai-Hulud worms that exploited automatic updates in open-source software repositories may be only the beginning, two researchers said at RSAC 2026.
Armenian Hambardzum Minasyan has been extradited to the U.S. to face charges related to his alleged involvement in the RedLine information-stealing operation, according to CyberScoop.
Security Affairs reports that the U.S. Department of Justice announced that Russian national Ilya Angelov has been sentenced to two years in prison, fined $100,000, and ordered to pay $1.6 million in money judgment over his co-management of the TA551 cybercrime operation, also known as Mario Kart, which launched a botnet used in ransomware attacks against U.S. organizations.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.