Venom Stealer MaaS Platform Commoditizes ClickFix Attacks
Venom Stealer is a malware-as-a-service platform automating ClickFix social engineering attacks. It enables even low-skilled threat actors to launch phishing campaigns with automated tools.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Venom Stealer is a malware-as-a-service platform automating ClickFix social engineering attacks. It enables even low-skilled threat actors to launch phishing campaigns with automated tools.
Attackers exploit valid credentials and routine access instead of sophisticated exploits. Organizations often overlook this risk while investing in patching and advanced defenses.
** Google patched an actively exploited Chrome zero-day (CVE-2026-5281) — a use-after-free in the WebGPU Dawn component. Update Chrome immediately; no user interaction needed for exploitation.
** Microsoft warns of active campaign delivering malicious VBS files via WhatsApp that bypass Windows UAC to gain admin privileges and establish persistent remote access on compromised systems.
** Blanket AI bans don't stop usage — they kill visibility. Leading CISOs are replacing prohibition with prompt-level governance, AI gateways, and data-centric policies.
Cybersecurity AI trained on historical threats creates blind spots for novel attacks. Emerging threat actors and unconventional methodologies outside training data leave organizations dangerously exposed.
Google attributed an Axios npm supply chain attack (2M+ weekly downloads) to North Korean threat actor UNC1069. Trojanized package versions were distributed via npm, demonstrating how nation-states increasingly target critical open-source dependencies for financial gain and persistent system access.
Attackers are abandoning malware for "living off the land" tactics, weaponizing legitimate OS tools like PowerShell and admin utilities to bypass traditional defenses. Organizations remain exposed because their security infrastructure is calibrated to detect malware, not attacks using trusted system
Axios NPM package was compromised for 8-12 hours; malicious versions 0.27.3 & 0.28.1 exfiltrated developer credentials before NPM's security team detected and removed them. The attack targeted the publishing mechanism rather than source code and is suspected to be North Korean-backed.
TeamPCP is rapidly escalating attacks on AWS, Azure, and SaaS platforms using stolen credentials obtained through phishing and credential stuffing. Organizations face a shrinking detection window as cloud environments lack traditional perimeter defenses, enabling faster attacker persistence.
Palo Alto discovered a critical Vertex AI vulnerability where over-privileged agents enable attackers to steal sensitive data, escalate privileges, and compromise cloud infrastructure through prompt injection attacks. The flaw exposes a broader risk: AI agents deployed with excessive permissions cre
**Summary:** PX4 Autopilot has a critical flaw (CVE-2026-1579) enabling unauthenticated remote command injection through disabled default message signing. Attackers with network or physical access can execute arbitrary commands on thousands of commercial drones and defense systems.
** Google is rolling out mandatory identity verification for all Android developers, starting in four countries by September before going global in 2027, aiming to stop malware distributors from hidin
Iranian APTs resume Pay2Key operations using 'pseudo-ransomware'—threatening data disclosure and disruption without encryption to extort US targets for millions in ransom.
Mid-market security teams should prioritize fast remediation of relevant threats over tracking thousands of irrelevant CVEs. Speed matters more than volume for effective vulnerability management.
CVE-2026-3502 in TrueConf allows attackers to inject malware into software updates by exploiting inadequate signature verification. The TrueChaos campaign actively targets Southeast Asian governments using this flaw, enabling persistent backdoor access to critical networks. **(179 characters)**
Credential theft fuels ransomware and nation-state cyberattacks. Billions harvested annually and sold on darknet markets, democratizing cybercrime for attackers of all sophistication levels.
AI-accelerated development multiplies code output tenfold while AppSec practices remain static, overwhelming security teams. The industry must evolve to secure the volume of auto-generated code.
A Chinese cyber operation distributes AtlasCross RAT malware through typosquatted domains targeting Chinese-speaking users. The remote access trojan compromises financial apps, messengers, and VPNs, with 11+ confirmed malicious domains enabling remote control, keylogging, and credential theft.
** AI is accelerating cyberattacks from weeks to hours. Unified Exposure Management merges siloed security tools into one risk model, giving boards actionable insight to keep pace.
Lloyds' faulty software update exposed 450,000 users' transaction data, allowing customers to view others' financial transactions. The breach reveals inadequate testing procedures in financial services and serious privacy violations under GDPR and FCA regulations.
Google's research shows quantum computers need only 1.9 billion qubits—20x fewer than estimated—to break Bitcoin and Ethereum encryption, urgently raising cryptocurrency security concerns.
Maryland man charged with $53M Uranium Finance theft via smart contract exploits. Used crypto mixer to launder stolen funds. Faces wire fraud, money laundering, and computer fraud charges.
DeepLoad hides credential-stealing malware in AI-generated junk code to evade detection. It targets browsers, email, VPNs, and SSH keys, signaling attackers leveraging AI against security defenses.