Policy & Government
FBI Arrests 21-Year-Old Zyaire Wilkins Over Steam-Game Malware Campaign Draining Crypto Wallets
A cryptocurrency-user targeting arrest via a novel Steam-games vector — law-enforcement coverage this weekend.
Understand the impact of malicious software on your digital security. Explore our guides on malware types, detection signs, and professional removal strategies to stay protected.
Policy & Government
A cryptocurrency-user targeting arrest via a novel Steam-games vector — law-enforcement coverage this weekend.
Threat Intelligence
A botnet targeting self-hosted AI tooling for cloud keys — defender review for organizations exposing AI services this weekend.
Supply Chain Attack
Another JavaScript-ecosystem compromise with a novel blockchain-C2 angle — seven scoped npm packages impersonating the Vite tooling namespace, and defender inventory work this weekend.
Nation-State Cyber Threats
Another Southeast-Asia-focused espionage cluster documented by Kaspersky — a defender research review this week for government and diplomatic entities in the region.
Threat Intelligence
Another named stealer joins the ClickFix pattern — a defender posture review across Microsoft 365 environments after Microsoft's published analysis this week.
Nation-State Cyber Threats
Another Contagious Interview variant with a novel SVG delivery angle — a defender-oriented research review of how North Korea-linked actors hid an OtterCookie-aligned payload inside flag images sent through fake coding challenges.
Malware
A Rust-based Windows remote-access tool with an NVIDIA-impersonation posture — defender research this week from Blackpoint Cyber, published with indicators of compromise for detection teams.
Nation-State Cyber Threats
A dormant China-linked kernel rootkit surfaces again in Taiwan with a new backdoor companion — defender research review this week.
Malware
A novel macOS stealer technique with credential-and-crypto targeting — defender posture review for Mac-issuing organizations this week.
Supply Chain Attack
Another JavaScript-ecosystem supply-chain compromise, confirmed by four vendors: four @asyncapi npm packages were observed distributing a multi-stage botnet loader, and all five malicious versions have since been pulled from npm — defender inventory work this week.
Supply Chain Attack
A large-scale JavaScript-ecosystem supply-chain compromise — defender inventory work this week.
Malware
A macOS notarization-abuse malware disclosure — defender review for Mac-issuing organizations this week.