« Reports in 2026

554 reports

2026-04-15 • Zerion

Zerion says a team member’s device was compromised in an AI-enabled social engineering attack linked to a DPRK threat actor. The attacker gained access to logged-in sessions, credentials, and private keys for internal company hot wallets, leading to about…

#Zerion
2026-04-13 • Bitso

Bitso describes renewed Famous Chollima activity against crypto and financial organizations, including a suspicious job applicant encounter and a macOS malware kit the researchers call Mach-O Man. The infection chain starts with hijacked Telegram accounts…

#FamousChollima #ClickFix
2026-04-11 • Break Glass Intelligence

Breakglass analyzed a live Kimsuky C2 tied to a CHM-based intrusion chain after a MalwareBazaar submission exposed check.nid-log[.]com serving multiple payload stages. The chain uses hh.exe, PowerShell, certutil, and wscript to decode and execute VBScript…

#CHM #Kimsuky #T1082 #T1140 #T1041 #T1071.001 #T1115 #T1083 #T1056.001 #T1204.002 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1059.001 #T1036.005 #T1053 #T1132.001
2026-04-10 • Open AI

OpenAI identified exposure to the broader Axios supply-chain compromise when a GitHub Actions workflow used for macOS app signing downloaded and executed malicious Axios version 1.14.1 on March 31, 2026. The affected workflow had access to certificate and…

#Axios