Microsoft is calling attention to an ongoing malvertising campaign that makes use of Node.js to deliver malicious payloads capable of information theft and data exfiltration.
The activity, first detected in October 2024, uses lures related to cryptocurrency trading to trick users into installing a rogue installer from fraudulent websites that masquerade as legitimate software like Binance or TradingView.
Russia’s Moscow Exchange (MOEX) is moving to broaden which digital assets it tracks and trades. Reports say the exchange plans to roll out new indices and futures tied to XRP, Solana, and Tron this year. That will give t…
www.osintinvestigate.comDomains set up by the threat actor suggest attacks aimed at Atlassian, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, and WeWork.
www.osintinvestigate.com Marketed as ChatGPT enhancement and productivity tools, the extensions allow the threat actor to access the victim’s ChatGPT data.