Research
-
Japan military used infected USB drives linked to China-based hacking in nearly year-long breach
Japan’s Ground Self-Defense Force used counterfeit USB drives infected with malware on sensitive networks for nearly a year after they entered service during earthquake relief work, according to a Nikkei Asia investigation and leaked internal documents.
-
Fake Perplexity Chrome extension tracked searches on Chrome Web Store
A malicious Chrome Web Store extension posing as Perplexity AI intercepted search traffic and collected browsing data, Microsoft said in a technical analysis. The company found no credential theft, but warned the permissions could enable broader abuse.
-
Google details Turla’s STOCKSTAY backdoor used against Ukraine and European targets
Google said Turla used a previously undocumented .NET backdoor called STOCKSTAY against government and military targets in Ukraine and other European entities, with activity dating to December 2022 and delivery through phishing and archive-based lures.
-
Amazon Q Developer flaw let malicious repos run code and expose cloud credentials
Amazon Q Developer had a flaw that let a malicious repository run code and expose cloud credentials, according to Wiz Research. AWS says the issue is fixed, and customers are being urged to update affected plugins and language servers.
-
macOS flaw let standard users disable CrowdStrike and Kandji tools, researchers say
Researchers said a macOS flaw let standard user accounts disable major enterprise security tools, including CrowdStrike Falcon Sensor and Kandji, by abusing XPC communication. Vendors have patched the issue or are working on fixes.
-
Mirage2FA phishing kit uses HTML smuggling to target Microsoft 365 users
Fortra identified Mirage2FA, a phishing kit that uses HTML smuggling and obfuscated JavaScript to mimic Microsoft 365 sign-in pages and steal credentials during MFA prompts in an email campaign tied to cheacker[.]store.
-
Microsoft flags photo ZIP phishing campaign targeting hotels in Europe and Asia
Microsoft said a phishing campaign has targeted hotels and other hospitality organizations in Europe and Asia since April 2026, using photo-themed ZIP files to install a Node.js implant and gain access to front-desk machines.
-
Fake GTA 6 early access sites push crypto scam and malware, reports say
Fake websites are using interest in Grand Theft Auto VI to sell nonexistent early access for cryptocurrency, security researchers say. The scam can also install malware on PC and Android devices.
-
Malwarebytes warns of parcel mule job scams posing as remote work
Malwarebytes says scammers are using fake remote job offers, including “Parcel Expert” roles, to recruit parcel mules who receive and forward stolen goods from home. The company warns of fraud, identity theft and possible law enforcement contact.
-
Mistic backdoor tied to ransomware access broker in attacks on multiple sectors
A new backdoor called Mistic has been used since April in attacks on insurance, education, IT and professional services firms, with researchers linking it to a ransomware access broker that sells network access.






