A new phishing kit is being offered on Telegram allowing even newbie hackers an easy way to grab OAuth tokens.
CISA has already added the flaw to its KEV database.
Ransomware actors use a whole range of different tactics to persuade victims to pay the demands.
A TeamPCP copycat was just spotted hitting thousands of GitHub repos with an infostealer.

“Social engineering” sounds like something out of a conspiracy thriller, charged with totalitarian control and fringe paranoia. More mundanely, it’s come to be associated with phishing and other scams, in which fraudsters manipulate people into disclo…
Anthropic illustrates the first months of Mythos Preview, saying it discovered thousands of critical and high-severity bugs.
…
As attackers ramp up their AI exploit development, the search for software vulnerabilities is changing rapidly.

On March 31, 2026, Anthropic accidentally shipped the entire source code of Claude Code to the public npm registry. Around 512,000 lines of TypeScript across 1,906 files, including 44 hidden feature flags and references to an unreleased model codenamed…

This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on AI mischief, follow Robert Hart. The Stepback arrives in our subscribers’ inboxes at 8AM ET. Opt in for The Stepback here. How it started Hacking the first generation of AI chatbots was a laughably simple affair. […]
AMOS malware spreads on macOS through social engineering, stealing credentials while researchers debate whether its threat level is truly novel.
…