www.gamingonlinux.com
The Arch Linux AUR had over 400 packages compromised with malware
Looks like the Arch Linux AUR (Arch User Repository) needs some better security and package checks - as some malicious users compromised a lot of packages.
#Malware is an active hashtag on Bluesky. In the last 30 days, 154 people shared 1,204 posts with it — around 40 a day. Activity is down 15% versus the previous week, peaking on Aug 31 with 89 posts.
Tags most often used together with #Malware.
www.gamingonlinux.com
The Arch Linux AUR had over 400 packages compromised with malware
Looks like the Arch Linux AUR (Arch User Repository) needs some better security and package checks - as some malicious users compromised a lot of packages.
www.heise.de
LastPass entdeckt neue Infostealer-Variante, die sich als GitHub-Repo tarnt
Gefälschte GitHub-Repositorys sollen Opfer zum Download bewegen. Ein Infostealer arbeitet mit Signaturen aus Microsofts Hardware-Kompatibilitäts-Programm.
flipboard.social
Original post on flipboard.social
thehackernews.com
Wanted Russian Cybercriminal Linked to Hive and LockBit Ransomware Has Been Arrested
Russian authorities arrest Mikhail Matveev, key LockBit and Hive ransomware hacker, charged with global cyberattacks.
www.bleepingcomputer.com
FBI wipes Chinese PlugX malware from over 4,000 US computers
The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States.
www.theregister.com
Google Pixel phones pwned in zero-click attacks
CISA gives federal agencies just 3 days to patch
malware.news
2026-09-14: Backdoor using ScreenConnect from malicious emailt - Malware Analysis - Malware Analysis, News and Indicators
Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor. Enroll Now and Save 10%: Coupon Code MWNEWS10 Note: Affiliate link – your en…
commons.now
New Android Malware Uses AI to Steal Bank Logins and Reconstruct Your PIN
A newly identified Android banking Trojan called RatHat uses phone features for account theft. The malware can guide itself through an infected device, capture banking logins, intercept verification …
pkgradar.com
PkgRadar coverage
What we're seeing across the ecosystems, from our own scan data.
pkgradar.com
This week in supply-chain malware
PkgRadar's live view of malicious-package activity across nine ecosystems.
pkgradar.com
Flagged first: npm [email protected]
PkgRadar flagged this 1 day before MAL-2026-16332 was published. See the dated receipt and static evidence.
pkgradar.com
Flagged-first coverage
18 malicious packages flagged across npm, before their public advisories.
commons.now
Hackers Hide XMRig Miner in Windows Registry, PNG and WAV Files to Evade Detection
Hackers are using a layered Windows malware chain to run an XMRig cryptocurrency miner while keeping its key parts out of sight. The operation hides code in the Windows Registry, a PNG image, and fil…
cibered.com
El ataque que convirtió un paquete de gráficos en una máquina de robar credenciales | Noticias de Seguridad Informática | CIBERED
Ataque de cadena de suministro a npm @antv: payload roba credenciales de GitHub Actions. GitHub elimina 640 paquetes e invalida 61.274 tokens.
dlvr.it
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.