Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam

Microsoft researchers warn of a new ClickFix campaign targeting macOS with fake guides on Medium and Craft to deploy AMOS and SHub Stealer via Terminal commands. Continue reading Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam

ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data

The ClaudeBleed vulnerability allows hackers to bypass Claude for Chrome guardrails to exfiltrate private Google Drive and Gmail data. Continue reading ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data

Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware

Researchers have discovered a new malvertising campaign using a fake Claude AI website to plant a new, undocumented backdoor named Beagle on user devices. Continue reading Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware

Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams

Scammers are hiding invisible text inside phishing emails to manipulate AI-powered email filters and increase the chances of scams reaching inboxes. Continue reading Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams

Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE

Google patches a CVSS 10 Gemini CLI vulnerability that allowed hackers to use prompt injection and privilege escalation for a full supply chain compromise. Continue reading Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE