Windows devices are being compromised with the Oyster backdoor through bogus Microsoft Teams installers spread in a new malvertising and SEO poisoning campaign, reports BleepingComputer.
Attacks exploiting the Cisco Adaptive Security Appliance zero-days CVE-2025-20362 and CVE-2025-20333 were noted by the UK's National Cyber Security Centre to have deployed the newly emergent RayInitiator and LINE VIPER malware strains as part of a more sophisticated and clandestine campaign, Security Affairs reports.
Augmented browser targeting and persistence, as well as clipboard takeover capabilities, have been integrated into the updated version of the XCSSET macOS malware deployed in limited intrusions, BleepingComputer reports.
Suspected Vietnamese hackers have deployed the PureRAT trojan as part of a phishing campaign that initially involved a basic Python-based information-stealing payload, reports Infosecurity Magazine.
Nefarious Rust crates set sights on crypto wallet keys BleepingComputer reports that developers' cryptocurrency wallet keys and other secrets have been pilfered by a pair of Rust packages on Crates.io masquerading as the legitimate 'fast_log' crate.