A sophisticated new threat called OkoBot malware is targeting cryptocurrency users worldwide. The framework can deploy more than 20 malicious payloads to steal wallet recovery phrases, login details, browser cookies, and other sensitive information. The campaign relies on several infection methods. These include fake software repositories and ClickFix attacks that trick users into running malicious…
Japan’s largest taxi operator, Nihon Kotsu, is recovering from a cyberattack that forced the company to shut down parts of its IT infrastructure. The attack disrupted several customer services, including the company’s taxi dispatch system, which remains unavailable. Investigators are also examining whether any customer or company data was exposed during the incident. Malware Attack Forces…
Government cybersecurity agencies have warned that Russian state-backed hackers are targeting vulnerable routers to gain long-term access to critical infrastructure networks. The joint advisory says attackers are exploiting internet-facing network devices to collect sensitive information, map internal systems, and prepare future cyber operations. Security officials are urging organizations to strengthen router security before these devices…
The European Commission is preparing new legislation that could reshape how children access social media across the European Union. Commission President Ursula von der Leyen confirmed that a proposal will be presented after the summer, signaling a coordinated EU approach that could replace the patchwork of national policies emerging across member states. If adopted, the…
Anthropic has once again extended free access to Claude Fable 5 for eligible paid subscribers. The company has pushed the deadline to July 19, 2026, giving users another week before they need to purchase usage credits to continue using the model. The extension applies to several paid Claude plans and also keeps higher usage limits in place for…
Hackers compromised the Injective Labs SDK project and published a malicious npm package. The package stole cryptocurrency wallet private keys and mnemonic seed phrases. Security firms Socket, Ox Security, and StepSecurity detected the supply-chain attack. It affected version 1.20.21 of the @injectivelabs/sdk-ts package. Injective SDK Malware Reached npm Injective SDK is a TypeScript and JavaScript…
A New York man has been sentenced to federal prison after operating a crypto influencer impersonation scam that convinced victims to invest more than $1.4 million in fake cryptocurrency opportunities. Prosecutors say he used Telegram to impersonate well-known figures in the crypto community, attracting thousands of followers before directing victims into fraudulent investment schemes. Investigators…
A critical SimpleHelp vulnerability has become the latest target for cybercriminals, who are using it to compromise remote support servers and install a previously unseen malware toolkit designed to steal sensitive credentials. Security researchers uncovered the campaign after investigating attacks against vulnerable SimpleHelp deployments. Instead of stopping at unauthorized access, the attackers used the opportunity…
Prediction market platform Polymarket has pledged to reimburse customers who lost funds during a Polymarket supply chain attack that compromised part of its website. Attackers injected malicious JavaScript through a third-party frontend dependency, allowing them to trick users into approving fraudulent cryptocurrency transactions. The company said the incident affected only its website’s frontend and did…
Polish authorities have arrested four suspected members of a SIM swapping gang accused of stealing millions of dollars in cryptocurrency. Investigators say the group breached telecommunications partners, hijacked email accounts, and took control of victims’ phone numbers to access cryptocurrency exchange accounts. The operation involved the Polish Cybercrime Bureau (CBZC) with support from the FBI…