Rapuncel Infostealer Hides Behind Fake LastPass GitHub Pages
A new malware campaign is turning one of the most trusted names in password security into bait. Attackers built fake GitHub pages that pose as LastPass Authenticator and dozens of other apps. Anyone who downloads from them ends up with the Rapuncel infostealer. It also brings a driver that shuts off antivirus tools before the theft begins. How Fake GitHub

RatHat Android Malware Lets AI Take Over Your Phone
A new mobile threat has handed the boring part of phone hijacking to an AI model. Researchers at Zimperium have pulled apart RatHat, an Android malware family with an unusual trick. It ships live screen data to a well known AI assistant, then asks the model where to tap next. Scripted phone trojans break when an app changes its layout,

Attackers Hijack HBO Max Reddit Account in Malware Ad Scheme
Hackers took over the verified Reddit account that HBO Max uses to talk with fans, and they turned it into a malware tool. Over about two days, the hijacked profile ran 108 fake ads. Anyone who clicked risked infecting a Windows PC or Mac with programs that steal passwords, files, and crypto. Because the ads came from a trusted brand

Claude AI Abuse: Spy Groups Automate Their Attacks
Anthropic has published new findings on hackers who tried to turn its own AI tool into a weapon. The report covers cases of Claude AI abuse from December 2025 to August 2026. One case stands far above the rest, because a single actor fed 1.8 million Android apps into a pipeline built to hunt for hidden keys. How one Claude

Surfshark VPN Breach Hit Test Servers, Not User Data
One server set up the wrong way gave an outsider a view into Surfshark's engineering systems. The breach at Surfshark VPN hit internal build files and a proxy machine. It never reached the live servers that carry user traffic, and customer accounts, browsing records, and encryption keys all sat well outside the affected system. Surfshark posted its own incident report

Phishing Attack Hits Trezor Users After Email Provider Breach
Attackers have found a way to reach Trezor customers from an email address the company genuinely owns, which breaks the usual advice. On Wednesday, wallet owners began getting urgent alerts from help@trezor.io with the right branding and sender name. None of it came from the company. Trezor buyers are the target of a phishing attack that started with a break-in

DoppelCart Fake Shops: 119,000 Sites Stealing Card Data
Online shopping fraud has outgrown the clumsy knockoff sites of a decade ago. Researchers have now mapped a network of more than 119,000 domains that sell nothing at all. DoppelCart fake shops make up the whole cluster, and they copy real brands closely. Most buyers never spot the difference. German security startup Nebty found the network and ranks it as

Vietnam APIS Data Leak Exposes 220 Million Traveler Records
Every international flight starts with a quiet data transfer. Airlines collect your passport number, date of birth and seat number. Then they send it all to border officials before you board. Passengers never see that handoff and cannot opt out. Researchers have now found one of those systems sitting wide open. The Vietnam APIS data leak placed more than 220

Coder Cloudflare Breach Delivered Malware to Developers
A trusted software registry spent roughly 14 hours handing out poisoned code, and the developers pulling from it had no reason to suspect a thing. That is the short version of the Coder Cloudflare breach, an attack against a development platform used by Dropbox, Palantir, Square, Mercedes-Benz, and parts of the U.S. government. Attackers never edited a single line in

Fire Ant Hackers Hijack Cisco Routers to Spy on Networks
Routers rarely get attention. They sit in racks, push traffic, and run untouched for years at a time. That quiet reliability is exactly what Fire Ant hackers learned to exploit, because a compromised router watches everything and raises no alarm. Investigators recently unpicked a Chinese espionage operation that turned Cisco networking gear into long-term surveillance equipment. The group has moved
