PromptSpy Android Malware Uses Google Gemini to Adapt on Infected Phones
A newly documented Android spyware strain called PromptSpy uses Google Gemini during execution to help it interact with a victim’s phone screen and maintain persistence.…
A newly documented Android spyware strain called PromptSpy uses Google Gemini during execution to help it interact with a victim’s phone screen and maintain persistence.…
A Microsoft device code phishing campaign is abusing a legitimate sign-in flow to steal account tokens without sending victims to a fake Microsoft login page.…
Synology has fixed three vulnerabilities in MailPlus Server that could let attackers disrupt mail services, read or write arbitrary files, or access internal services on…
Google has patched a critical Gemini CLI vulnerability that could let attackers execute arbitrary code in certain automated development workflows. The issue affects Gemini CLI…
A new Windows malware campaign is targeting users in India through fake Income Tax assessment pages. The operation, tracked as TAX#TRIDENT, uses realistic tax notice…
Mozilla fixed 423 Firefox security bugs across April 2026 releases after using Claude Mythos Preview and other security testing methods to find flaws in the…
NWHStealer has returned with a more advanced delivery method that uses the Bun JavaScript runtime to infect Windows PCs. Security researchers say attackers are using…
PCPJack is a newly reported cloud-focused malware framework that targets exposed infrastructure, steals credentials, and spreads across additional systems. SentinelOne says the worm targets Docker,…
Microsoft will begin rolling out Entra passkeys on Windows in late April 2026, giving organizations a new phishing-resistant way to sign in to Microsoft Entra-protected…
CrowdStrike has disclosed a critical vulnerability in LogScale that can let a remote attacker read arbitrary files from the server without authentication. The flaw, tracked…
More than 1,370 internet-facing Microsoft SharePoint servers still appeared exposed to CVE-2026-32201 in recent Shadowserver tracking, days after Microsoft released fixes and CISA added the…
Torg Grabber is a newly tracked Malware-as-a-Service infostealer that has evolved quickly from simple Telegram-based data theft into a more mature operation with encrypted command-and-control…
Attackers have started using fake Google Forms as the front end for a malware campaign that delivers the PureHVNC remote access trojan. Security researchers say…
A long-running SEO poisoning campaign has been pushing fake download pages for more than 25 popular apps and tricking Windows users into installing AsyncRAT. Security…
A new social engineering campaign is using fake IT support calls and spam email to gain remote access, steal credentials, and deploy a customized version…