Sponsor of the Day:
Jerkmate
https://www.foxnews.com/tech/fake-windows-update-installs-hidden-malware
Fake Windows update page found to install password-stealing malware | Fox News
Apr 21, 2026 - A fake Windows update site uses a typosquatted domain mimicking Microsoft to deliver malware that steals passwords, payment details and login sessions from...
fake windowsstealing malwarefox newsupdatefound
https://www.theregister.com/2026/03/18/darksword_exploit_kit_steals_iphone/
Snoops plant info-stealing malware on iPhones, Google warns • The Register
Mar 18, 2026 - : Darksword is the second iOS exploit chain in a month
stealing malwaregoogle warnssnoopsplantinfo
https://www.stepsecurity.io/blog/supply-chain-security-alert-popular-nx-build-system-package-compromised-with-data-stealing-malware
s1ngularity: Popular Nx Build System Package Compromised with Data-Stealing Malware - StepSecurity
s1ngularity attack hijacked Nx package on npm to steal cryptocurrency wallets, GitHub/npm tokens, SSH keys, and environment secrets - the first documented case...
build systempackage compromiseddata stealingpopularnx
https://gynvael.coldwind.pl/?id=98
A malware "stealing" AppInit_DLLs entrypoint - gynvael.coldwind//vx.log
gynvael coldwind vxmalwarestealingdllsentrypoint
https://www.infoworld.com/article/4149909/pypi-warns-developers-after-litellm-malware-found-stealing-cloud-and-ci-cd-credentials-2.html
PyPI warns developers after LiteLLM malware found stealing cloud and CI/CD credentials | InfoWorld
Mar 25, 2026 - The compromised packages, linked to the Trivy breach, executed a three‑stage payload targeting AWS, GCP, Azure, Kubernetes configs, SSH keys, and automation...
litellm malwarefound stealingci cdpypiwarns
https://www.csoonline.com/article/4149905/pypi-warns-developers-after-litellm-malware-found-stealing-cloud-and-ci-cd-credentials.html
PyPI warns developers after LiteLLM malware found stealing cloud and CI/CD credentials | CSO Online
Mar 25, 2026 - The compromised packages, linked to the Trivy breach, executed a three‑stage payload targeting AWS, GCP, Azure, Kubernetes configs, SSH keys, and automation...
litellm malwarefound stealingci cdcso onlinepypi