Silver Fox APT Hits India, Russia with Tax Scams
Over 1,600 phishing messages from China-linked Silver Fox APT targeted India and Russia in tax-themed attacks delivering new malware. Details emerged May 04, 2026.
Over 1,600 phishing messages from China-linked Silver Fox APT targeted India and Russia in tax-themed attacks delivering new malware. Details emerged May 04, 2026.
A new Python-based backdoor called DEEP#DOOR uses ngrok tunneling to steal browser and cloud credentials. First spotted April 30, 2026. Details from The Hacker News and BleepingComputer.
On April 30, 2026, SAP-related npm packages were compromised in a supply chain attack dubbed mini Shai-Hulud, injecting credential-stealing malware into dev environments. Details reveal how attackers infiltrated trusted tools used by enterprise developers.
The Lotus wiper malware used sophisticated living-off-the-land techniques to destroy data at Venezuelan energy firms on April 30, 2026. Details reveal a stealthy, high-impact attack.
Over 70 cloned Open VSX extensions are distributing GlassWorm malware—sleeper payloads targeting developers. Here’s what builders need to know.
Vidar has overtaken the infostealer market after 2025’s Lumma and Rhadamanthys takedowns. Operators exploit gaps left by law enforcement. Cybersecurity teams face rising data theft risks.
VECT 2.0 ransomware permanently destroys large files due to a fatal flaw—recovery is impossible, even for attackers. More details April 28, 2026.
A top PyPI package with over 1 million monthly downloads was compromised via exploit, not stolen credentials, spreading malware to developers since April 2026. Details on the breach and fallout.
73 counterfeit VS Code extensions on Open VSX deliver GlassWorm v2 malware, targeting developers with stolen session tokens and credentials. Report published April 28, 2026.
UNC6692 deploys Snow malware via email bombing and social engineering. Attackers gain persistent access using Snowbelt, Snowglaze, and Snowbasin variants. Full analysis.