Attackers used trusted tools and legitimate-looking workflows in two notable H1 2026 attack chains. One campaign sent malware through compromised business email accounts, while another redirected cryptocurrency payments by replacing copied wallet addresses. The campaigns used different malware and infrastructure. However, both relied on the same weakness: users trusted actions that appeared normal before attackers…
A new ClickFix campaign targets macOS users with malware that steals cryptocurrency, browser passwords, Apple Keychain data and cached credentials. Huntress discovered the threat while responding to a ClickFix incident. Researchers say the Go-based malware can intercept cryptocurrency transfers and redirect funds before victims approve their transactions. Unlike many wallet-draining tools, this macOS crypto drainer…
Researchers believe a COLDCARD RNG flaw may have enabled attackers to steal an estimated $88.6 million in Bitcoin from thousands of hardware wallets. Galaxy Research linked the suspected exploit to several coordinated transaction waves that drained 1,367 BTC from 4,585 addresses. The activity began on July 30, roughly 30 hours before wallet maker Coinkite publicly…
Cisco has warned that attackers are exploiting a high-severity vulnerability in Secure Firewall Management Center software. The Cisco FMC static credential flaw can give remote attackers unauthorised access to vulnerable devices. Tracked as CVE-2026-20316, the issue involves built-in credentials for a low-privilege account. Cisco has released hot fixes for affected versions and says customers should…
Three Apple customers have sued the company after a fake Sparrow Wallet app allegedly stole $1.835 million in Bitcoin. The plaintiffs claim the fraudulent app appeared in the App Store despite Apple’s promises that its marketplace is safe and trustworthy. The lawsuit was filed in the US District Court for the Northern District of California.…
Apple is facing a crypto wallet lawsuit from three people who claim a fraudulent app on the App Store stole approximately $1.8 million in Bitcoin. The complaint, filed in California on 24 July, alleges that Apple failed to properly review and monitor software distributed through its marketplace. The plaintiffs argue that Apple promoted the App…
A large malvertising operation is using fake cryptocurrency and trading websites to deliver browser memory malware. Instead of sending a completed malicious file to victims, the campaign uses JavaScript to assemble the payload directly inside the browser. The operation has been active since late 2024. It targets retail traders and cryptocurrency investors through convincing copies…
A new ShinyHunters sextortion scam is using email addresses from previously leaked company databases to make false threats appear convincing. The emails demand $2,000 in Bitcoin and claim that hackers have recorded recipients through their devices. However, there is no evidence that the scammers accessed victims’ phones, computers, cameras or personal accounts. Instead, they appear…
The Ostium crypto theft saw attackers steal $23.75 million from the platform’s liquidity provider vault after compromising off-chain infrastructure used to supply price data. According to Ostium, the attackers submitted fraudulent price reports that appeared legitimate. They then quickly opened and closed large trading positions at manipulated prices, creating artificial profits and draining funds from…
The Kalshi surveillance team is under scrutiny after the prediction market detected suspicious trades linked to a White House employee. US regulators are investigating Gabriel Perez, a longtime teleprompter operator for President Donald Trump. He allegedly used advance knowledge of presidential speeches to place profitable trades. Kalshi identified the activity, froze the account, and reported…