Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before ...
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.
A federally appointed panel is urging the four Atlantic provinces to create a single electricity market, a central part of ...
Are you still 'using AI all by yourself'?Opening ChatGPT or Claude, typing in a prompt, copying and pasting the returned answer, and then typing in the next instruction—.This was the 'standard way of ...
By Gertrude Chavez-Dreyfuss NEW YORK, Sept 22 (Reuters) - The market for highly rated corporate credit has split in two: bonds issued by AI-related firms are being met with caution, while those sold ...
A low-cost AI-driven hacking campaign stole over 600,000 credit card records and spread payment skimmers across at least 119 ...
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server.
WordPress malware hides as a must-use plugin and uses blockchain C2 to steal data and persist on compromised sites.