WordPress Supply Chain Attack Hijacks ShapedPlugin Pro Plugins
A supply chain breach compromised ShapedPlugin’s Pro WordPress plugins, injecting a backdoor that exfiltrates credentials and drops a web shell. Learn the impact and remediation steps.
A supply chain breach compromised ShapedPlugin’s Pro WordPress plugins, injecting a backdoor that exfiltrates credentials and drops a web shell. Learn the impact and remediation steps.
A new Android banking trojan, Rokarolla, hijacks 217 banking and crypto apps, using 137 commands to steal credentials, disable protections, and gain admin control.
ClickFix is now the top infection vector for Macs, according to 9to5Mac’s Security Bite podcast. Here’s what devs and IT teams must do.
Hackers abuse Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign targeting Mac users.
The JDownloader website was compromised on May 05, 2026, serving malicious installers containing a Python-based remote access trojan. Full analysis of the attack and implications for developers. Read more.
A new trojan named TCLBanker targets 59 banking and cryptocurrency platforms, using a trojanized MSI installer to infect systems.
The PCPJack worm removes TeamPCP infections but steals credentials in AWS, Docker, and Kubernetes environments. Full analysis, May 08, 2026.
Australia’s ACSC warns of ClickFix attacks distributing Vidar Stealer malware, exposing sensitive information.
A counterfeit Claude AI website distributes Beagle, a new Windows backdoor malware posing as ‘Claude-Pro Relay.’ Details on infection chain and risks..
Disc Soft confirms DAEMON Tools Lite was compromised in a supply chain attack on May 07, 2026, distributing malware via official installers. New clean version released. .