Advertisement
SnappyClient C2 Implant Targets Crypto Wallets for Data Theft
A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.
Claudy Day: Prompt Injection and XSS Flaws Target Claude AI Users
Researchers uncover 'Claudy Day', a trio of vulnerabilities in Anthropic's Claude AI that allow data theft through malicious Google search results.
Ransomware TTPs Shift: From Cobalt Strike to Native Tools, Data Theft Surges
Ransomware actors are abandoning Cobalt Strike for native Windows tools as payment rates decline, leading to a significant surge in data theft.
Elementor Ally Plugin SQLi: Unauthenticated Data Theft Risk
An unauthenticated SQL injection vulnerability in the Elementor Ally WordPress plugin affects over 400,000 sites, risking sensitive data exposure.
Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer
Attackers are exploiting Chrome extension ownership transfers to weaponize QuickLens and BuildMelon tools for code injection and data harvesting.
Spanish Authorities Dismantle Anonymous Fénix Hacktivist Node
Spain's National Police arrested four members of Anonymous Fénix, a hacktivist group targeting government infrastructure with DDoS and data exfiltration.
Advertisement