Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments
Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.
Researchers at OpenSourceMalware discovered 16 typosquatted packages on RubyGems designed to deliver StubMaker, a Windows-based information stealer targeting browser credentials and cryptocurrency wallets. The malicious packages, identified on August 15, 2026, use names similar to legitimate gems to trick developers into installation. This campaign highlights the ongoing risk of dependency confusion attacks in open-source package ecosystems.
Read full article at The Hacker News ↗Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.
Three banking trojans are currently active threats: Manic, which incorporates spyware capabilities; Grandoreiro, which maintains persistent campaigns targeting victims in Latin America and Europe; and ToxicPanda 2.0, an expanded variant of the ToxicPanda malware. Security professionals should monitor these banking trojans as they demonstrate ongoing development and geographic targeting sophistication.
Researchers at KnowBe4 have identified a new variant of Agent Tesla malware employing innovative emoji-based code obfuscation techniques to bypass security detection systems. This v4 iteration represents an advancement in the malware's evasion capabilities, demonstrating attackers' ongoing efforts to stay ahead of traditional threat detection methods.
Threat actors are leveraging the popularity of AI tools by impersonating well-known brands like Perplexity, Claude, ChatGPT, and Copilot to distribute malware including information stealers, backdoors, and malicious browser extensions. According to Sophs' analysis of 12 months of managed detection and response cases, 34 confirmed instances of malicious AI-related activity were identified, demonstrating the effectiveness of AI brand impersonation as a social engineering vector.