HackRead reports that fake PNG files have been harnessed to obscure trojans across 19 malicious VSCode extensions as part of an advanced attack campaign that has been underway since February.
Attacks with the newly discovered AshTag malware suite have been launched by Hamas-affiliated advanced persistent threat operation WIRTE, also known as Ashen Lepus, against over a dozen Middle Eastern government and diplomatic organizations since 2020, The Hacker News reports.
Malicious Google Search ads redirecting to ChatGPT and Grok guides have been harnessed to distribute the Atomic macOS Stealer, or AMOS, malware as part of a ClickFix attack campaign, BleepingComputer reports.
Attacks exploiting the maximum severity React2Shell vulnerability in React Server Components, tracked as CVE-2025-55182, have enabled the deployment of several newly emergent malware payloads and cryptocurrency miners, according to The Hacker News.
Cybersecurity researchers at Bitdefender uncovered the threat within a torrent file, which employed a Living Off the Land (LOTL) technique to evade detection.