Fake CAPTCHA Malware Campaign Targets Everyday Web Visitors

A familiar verification screen can conceal commands built to steal passwords, sessions, and sensitive files.
Ransomware incidents and attacks

A familiar verification screen can conceal commands built to steal passwords, sessions, and sensitive files.

Cloud extortion increasingly begins with a stolen login, a hijacked session, or one convincing call to technical support.

Attackers deploy malware posing as Apple system utilities to harvest credentials from Mac users, exploiting trust in familiar interface design.

Qilin ransomware operators weaponize Windows replication to distribute encryption payloads across networks in minutes, exploiting trust placed in backup systems.

A single compromised code repository can distribute botnet malware across an entire organization, remaining hidden in build artifacts and version control history.

A sophisticated backdoor linked to state-sponsored operations resurfaces in Taiwan with expanded capabilities and heightened evasion techniques.

Repository compromises can inject botnet malware across development and production infrastructure, exploiting the trust developers place in their own code platforms.

A single compromised npm package can distribute malware to thousands of development teams within hours, yet most compromises go undetected for weeks.

Taiwan faces renewed threats as Daxin malware resurfaces with enhanced backdoor capabilities designed to evade modern security defenses.

Malware-injected npm packages spread silently through developer machines and build systems, potentially affecting millions of users before discovery.