Two malicious Visual Studio Code extensions, Bitcoin Black and Codo AI, were found on the VS Code marketplace, capable of stealing screenshots, browser sessions, and stored credentials. The extensions were reported by…
Western Digital has disclosed a critical vulnerability in its WD Discovery desktop application for Windows, tracked as CVE-2025-30248. This flaw affects version 5.2.730 and all prior releases, allowing attackers to…
APT24, a China-linked hacking group, has been utilizing a previously undocumented malware named BadAudio in a three-year espionage campaign. This malware has been delivered through various methods, including…
Since mid-2024, the threat group UNC1549 has conducted targeted cyber campaigns against the aerospace, aviation, and defense industries, particularly focusing on entities in the Middle East. Mandiant has documented…
The APT24 threat group, linked to China, has been conducting a cyberespionage campaign utilizing a newly discovered malware called BadAudio. This campaign has targeted over 20 legitimate public websites to deliver the…
Mandiant has identified a surge in targeted campaigns by the threat group UNC1549, suspected to be linked to Iran, focusing on the aerospace, aviation, and defense sectors in the Middle East. Since mid-2024, these…
PeckBirdy is a JScript-based command-and-control framework utilized by China-aligned APT groups to exploit LOLBins. Since 2023, it has been deployed against gambling industries and Asian government entities, delivering…