AI malware
-
Researchers show TrojPix air-gap attack can leak data at 8.1 Mbps
Researchers at Shandong University say a new air-gap attack called TrojPix can leak data from isolated computers through video cable emissions, reaching 8.1 Mbps in tests and a separate maximum range of 208 meters.
-
Japan military used infected USB drives linked to China-based hacking in nearly year-long breach
Japan’s Ground Self-Defense Force used counterfeit USB drives infected with malware on sensitive networks for nearly a year after they entered service during earthquake relief work, according to a Nikkei Asia investigation and leaked internal documents.
-
Fake GTA 6 early access sites push crypto scam and malware, reports say
Fake websites are using interest in Grand Theft Auto VI to sell nonexistent early access for cryptocurrency, security researchers say. The scam can also install malware on PC and Android devices.
-
144 Mastra npm packages hit by supply chain attack
A supply chain attack compromised 144 npm packages in the Mastra namespace in June 2026, with a malicious dependency used to drop payloads that could steal wallet data, browser information and credentials.
-
New Rokarolla Android malware targets banking and crypto apps
A new Android banking trojan called Rokarolla targets 217 banking and cryptocurrency apps, uses 137 commands and can steal credentials, SMS codes and crypto payments, according to a technical analysis by Zimperium’s zLabs.
-
Microsoft removes 73 GitHub repositories during malware investigation
Microsoft removed 73 GitHub repositories on June 5 while investigating potential malicious content, briefly disrupting developer pipelines tied to Azure Functions. Researchers linked the incident to a broader Miasma and Shai-Hulud supply-chain campaign.
-
New npm supply chain worms hit 50-plus packages, steal secrets
Two npm supply chain attacks spread a Rust information stealer and a worm across dozens of packages, targeting developer secrets, cloud credentials and AI tool configurations. Researchers said the malware used GitHub and npm features to keep propagating.
-
Fake open-source tool sites used to push malware through gated redirects
Researchers say fake sites impersonating open-source tools such as Ghidra and dnSpy are using gated redirects to push malware, including Remus Stealer, AnimateClipper and SessionGate, after users click download buttons.
-
WeedHack malware campaign infects more than 116,000 Minecraft systems
A malware campaign called WeedHack has infected more than 116,000 Minecraft systems since January, using fake mods and clients promoted through YouTube and search poisoning to steal credentials and other data.
-
GREYVIBE campaign targets Ukraine with phishing, fake sites and AI tools
GREYVIBE has targeted Ukraine-linked entities since at least August 2025 using phishing, fake CAPTCHA pages and fraudulent websites, while a WithSecure analysis says the group appears to have used AI tools to speed malware development.








