New font-rendering trick hides malicious commands from AI tools
(bleepingcomputer.com)
1.
2.
Xygeni GitHub Action Compromised Via Tag Poison
(darkreading.com)
3.
4.
Why the shift left dream has become a nightmare for security and developers
(bleepingcomputer.com)
5.
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
(darkreading.com)
6.
Google says its AI systems helped deter Play Store malware in 2025
(techcrunch.com)
7.
CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups
(bleepingcomputer.com)
8.
Fake job recruiters hide malware in developer coding challenges
(bleepingcomputer.com)
9.
Claude LLM artifacts abused to push Mac infostealers in ClickFix attack
(bleepingcomputer.com)
10.
Microsoft: New Windows LNK spoofing issues aren't vulnerabilities
(bleepingcomputer.com)
11.
12.
Fake AI Chrome extensions with 300K users steal credentials, emails
(bleepingcomputer.com)
13.
14.
Malicious 7-Zip site distributes installer laced with proxy tool
(bleepingcomputer.com)
15.
More Mac malware from Google search
(news.ycombinator.com)
16.
Ransomware gang uses ISPsystem VMs for stealthy payload delivery
(bleepingcomputer.com)
17.
18.
Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days
(darkreading.com)
19.
Notepad++ users take note: It's time to check if you're hacked
(arstechnica.com)
20.
New GlassWorm attack targets macOS via compromised OpenVSX extensions
(bleepingcomputer.com)
21.
Notepad++ Compromised By State Actor
(slashdot.org)
22.
Russian hackers exploit recently patched Microsoft Office bug in attacks
(bleepingcomputer.com)
23.
24.
25.
Malicious MoltBot skills used to push password-stealing malware
(bleepingcomputer.com)
26.
27.
28.
29.
eScan confirms update server breached to push malicious update
(bleepingcomputer.com)
Today's top topics:
anthropic