Russian hackers are trying to sneak infostealers onto people’s devices to grab passwords, crypto, and more.
Almost a dozen vulnerable UEFI shim bootloaders discovered and revoked.
Microsoft shipped three times more fixes than usual in its latest Patch Tuesday update.

‘Gold Eagle’ scheme looks to centralize vulnerability identification and remediation for maximum efficiency.
Visited domains were being exfiltrated to a third-party server, seemingly under a Chinese actor’s control.
Greater visibility, better detection, and stronger governance over OAuth-connected applications should mitigate ShinyHunters attacks.
Russians are targeting misconfigured routers running in critical infrastructure firms.
Researchers found a new piece of macOS malware grabbing passwords, crypto data, and more.
Nihon Kotsu suffers malware attack, but there’s no evidence of data exfiltration yet.
Ransomware negotiator served 70-month prison sentence, and will have to forfeit everything he’s gained.