Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits.

In a proof of concept, they rec… Continue reading Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

Posted in Uncategorized

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Scanners meant to catch malicious add-on “skills” for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology.

The… Continue reading SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Posted in Uncategorized

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRi… Continue reading North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

Posted in Uncategorized

New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out.

Bad Epoll sits in the same sm… Continue reading New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

Posted in Uncategorized

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft.

According to JFrog, the packages “rollup-packages-polyfill-core” an… Continue reading North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Posted in Uncategorized

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.

“Armored Likho blends financially motivated campaigns… Continue reading Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

Posted in Uncategorized