Breaking News – Cyber Threats (last 6h)
Generated: 2026-08-03 17:00 PDT
- New Pass-ta-key attacks let malware hijack Google-synced passkeys
BleepingComputer • 2026-08-03 16:58 • www.bleepingcomputer.com
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. […]
https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/ - New DOUBLECUP ClickFix service hides malware in browser cache images
BleepingComputer • 2026-08-03 13:01 • www.bleepingcomputer.com
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. […]
https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/ - Fake Roblox Xeno script launcher pushes infostealer, RAT malware
BleepingComputer • 2026-08-03 12:25 • www.bleepingcomputer.com
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. […]
https://www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/ - 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
The Hacker News • 2026-08-03 11:43 • thehackernews.com
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package
https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
