This week’s cybersecurity recap covers rogue AI behavior, an exploited Metabase zero-day, MCP supply-chain attacks, router backdoors, and more.
DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the ...
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by ...
In late January 2026, security researchers found that 12% of all ClawHub skills were malicious — 341 out of 2,857 skills across multiple campaigns. By mid-February, this expanded to 824+ malicious ...
All payloads use api: "every" meaning they are available to every customer, not restricted by API key. The earliest payload dates to November 2024, proving the operation has been actively maintained ...
More than a dozen US-based web servers were used to host 10 malware families, distributed through mass phishing campaigns. Malware families include Dridex, GandCrab, Neutrino, IcedID and others.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results