Malicious actors have leveraged the novel Ghost Crypt crypter to compromise a U.S.-based accounting firm with the PureRAT trojan in a May cyberattack, Infosecurity Magazine reports.
Updated DCHSpy spyware variants spread in MuddyWater attacks Iranian state-sponsored advanced persistent threat operation MuddyWater, also known as Static Kitten, SeedWorm, and TEMP.Zagros, has launched attacks involving four new variants of its DCHSpy Android spyware amid Iran's ongoing conflict with Israel, reports Security Affairs.
Over 3,500 websites around the world have been infected with JavaScript cryptocurrency mining malware as part of a new cryptojacking campaign, The Hacker News reports.
Five popular JavaScript libraries, including the 'eslint-config-prettier' npm package, have been compromised to become malware droppers following a supply chain intrusion stemming from the successful phishing of their maintainer JounQin, BleepingComputer reports.
Attacks exploiting fraudulent artificial intelligence platforms have been launched by the EncryptHub threat operation to compromise Web3 developers with the information-stealing malware, reports The Hacker News.
Threat actors have been leveraging a pair of zero-day vulnerabilities impacting Ivanti Connect Secure appliances, tracked as CVE-2025-0282 and CVE-2025-22457, to deploy the new MDifyLoader malware as part of attacks that have been underway since December, according to The Hacker News.