Cybercrime
-
Three critical bugs in Picklescan could let malicious PyTorch models execute code, researchers say
Researchers disclosed three high-severity vulnerabilities in Picklescan that can be abused to bypass scanning and execute arbitrary code when loading malicious PyTorch models; fixes were released in Picklescan 0.0.31 and related analysis is available from JFrog, SecDim and others.
-
Malicious Rust crate ‘evm‑units’ delivered cross‑platform payloads and targeted Web3 developers
A malicious Rust crate named evm‑units masqueraded as an Ethereum helper and delivered platform‑specific payloads to Windows, macOS and Linux machines. Published by a crates.io user called ablerust and included as a dependency of uniswap‑utils, the package fetched and executed scripts or PowerShell based on the host OS and the presence of Qihoo 360 antivirus,…
-
Kensington and Chelsea says data was copied during London councils IT outage
Kensington and Chelsea Council said evidence shows some data was copied and removed during a recent cyber incident affecting a shared IT environment used by three London councils. The authority has not specified what was taken, who is affected or how long attackers had access, and investigations by the NCSC and the Metropolitan Police are…
-
Iran-linked MuddyWater group deploys MuddyViper backdoor against Israeli targets
Researchers say Iranian-linked MuddyWater has used a new MuddyViper backdoor, delivered via a Fooder loader, to target Israeli organisations across multiple sectors and to harvest credentials and browser data.
-
Glassworm malware returns with 24 malicious VS Code packages on OpenVSX and Microsoft marketplace
The Glassworm malware has returned in a third wave with 24 malicious VS Code extension packages on OpenVSX and the Microsoft Visual Studio Marketplace, using obfuscation and Rust‑based implants to steal credentials, deploy proxies and enable remote access.
-
Authorities shut down cryptocurrency mixer Cryptomixer, seize nearly $28 million in Bitcoin
European authorities shut down the cryptocurrency mixer Cryptomixer and seized nearly $28 million in Bitcoin, servers and data in an operation Europol said was part of a wider effort to disrupt money laundering tied to ransomware, fraud and other crimes.










