Chinese cybercrime group expands operations into Europe with new malware
TA4922 now conducts more unique campaigns than any other cybercrime actor, says Proofpoint.
TA4922 now conducts more unique campaigns than any other cybercrime actor, says Proofpoint.
The framework's code and payloads were developed using AI agents powered by Cursor and Claude Opus.
The malware spreads through fake Minecraft mods, cheats, clients, and other tools.
The attackers tricked the AI into linking their own email addresses to targeted accounts.
CISA didn’t provide any details on the nature of the exploitation of the vulnerabilities.
An unknown threat actor attempted to bypass two-factor authentication and add new devices to existing user accounts.
The campaign begins with weaponized xHTML files that deliver a malicious RAR archive exploiting a WinRAR vulnerability (CVE-2025-8088).
The attack is designed to steal developer credentials and CI/CD secrets during package installation.
The campaign mainly targets organizations in government, research, education, technology, and financial services.
The Marimo flaw was exploited for the initial compromise and AWS credential theft.
Showing elements 111 - 120