This week’s cybersecurity recap covers rogue AI behavior, an exploited Metabase zero-day, MCP supply-chain attacks, router backdoors, and more.
DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the ...
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by ...
In late January 2026, security researchers found that 12% of all ClawHub skills were malicious — 341 out of 2,857 skills across multiple campaigns. By mid-February, this expanded to 824+ malicious ...
All payloads use api: "every" meaning they are available to every customer, not restricted by API key. The earliest payload dates to November 2024, proving the operation has been actively maintained ...
More than a dozen US-based web servers were used to host 10 malware families, distributed through mass phishing campaigns. Malware families include Dridex, GandCrab, Neutrino, IcedID and others.