Tag: spyware
52 articles

Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Seeds
Researchers uncovered 13 malicious packages on Packagist that inject JavaScript into popular Vietnamese streaming sites, unleashing a two-pronged attack that includes mobile ad-fraud and spyware installation on unpatched iPhones. This sneaky malware can steal crypto seeds and wreak havoc on unsuspecting users.

Manic Android Malware Exploits Nearby Devices for Data Exfiltration
Meet Manic, a sneaky new Android malware that's using a clever fallback strategy to steal sensitive data from nearby devices, even when they have no internet connection. It captures credentials and in-app secrets by combining spyware, banking fraud, and remote-control capabilities into one powerful payload.

Apple patches image-processing flaw exploited in spyware campaigns
Apple just patched a major security flaw in its ImageIO system that could let attackers run code on your device - and it's already been used in sneaky spyware campaigns targeting high-profile targets.

US Military Left Vulnerable to Telecom Attacks
The US military's vulnerability to telecom attacks has been exposed, with numerous successful breaches resulting in stolen location data, intercepted communications, and even manipulation of American voters through text messages. This alarming threat isn't caused by a new malware strain, but rather a decades-old signaling system that underpins global telephony and has been left open to exploitation.

NSO Group Defies Court Order, Continues Targeting WhatsApp Users
Despite a court order blocking it from doing so, NSO Group continues to target WhatsApp users, defying the ruling and putting users at risk. The company is fighting to overturn the order, claiming it will suffer harm if it's forced to comply.

WhatsApp Disrupts NSO Group's Spearphishing Campaign
WhatsApp has successfully shut down a sneaky phishing campaign by notorious spyware firm NSO Group, which tried to trick users into clicking malicious links to spy on them. The messaging giant is now asking a US court to hold NSO Group accountable for violating a ban on targeting users.

Meta Alleges NSO Group Breaches Spyware Injunction
Meta just took a bold stand against NSO Group, the notorious spyware maker, by ramping up legal action after thwarting a sneaky phishing campaign aimed at WhatsApp users. The tech giant successfully blocked NSO-linked attempts to trick people into clicking malicious links, despite a US court injunction already in place.

WhatsApp Disrupts NSO Group's Spyware Phishing Campaigns
Meta's WhatsApp team swiftly sprang into action, disrupting a sophisticated spyware phishing campaign linked to the NSO Group after investigating user reports of targeted social-engineering attacks. They successfully stopped the attackers' attempts to trick people into clicking malicious links that could have put their data at risk.

Meta Accuses NSO Group of Breaching WhatsApp Injunction
Meta is taking a stand against NSO Group, accusing the Israeli spyware vendor of breaching a WhatsApp injunction by targeting users with social engineering attempts. The company claims it successfully thwarted these malicious efforts, but is now asking a federal judge to hold NSO Group in contempt.

Google Bolsters Android Spyware Defenses with Intrusion Logging Feature
Google just launched a game-changing feature to help protect Android users from spyware: Intrusion Logging, a powerful tool that collects forensic data to help investigate suspected device compromises. Now available in Advanced Protection Mode, this innovative feature lets users opt-in to safeguard their digital security and peace of mind.

Google Bolsters Android Security to Counter Spyware Vendors
Google's new Intrusion Logging feature is a game-changer in the fight against spyware, helping digital forensics researchers uncover sophisticated attacks on Android devices. By recording security incidents like device unlocking and spyware installation, it provides crucial evidence to investigate and take down these threats.

Malicious AI Browser Extensions Exfiltrate User Data
Beware of AI browser extensions that promise to boost productivity but secretly steal your data. Researchers uncovered 18 malicious extensions that masquerade as helpful tools but deliver spyware, Trojans, and other threats that can hijack your online activity.

Kaspersky Uncovers CrystalX RAT with Extensive Spyware and Stealer Capabilities
Meet CrystalX, a sinister new remote-access tool that's being sold as a ready-made menace, packing an alarming combination of spyware, stealer, and prankware capabilities that put your digital security at risk. This malicious toolkit is the latest threat to watch out for, and Kaspersky researchers are sounding the alarm.

Congress Probes ICE's Use of Paragon Spyware
House Democrats are pushing back against Immigration and Customs Enforcement's use of Paragon spyware, demanding more answers after the agency's explanations fell short. The lawmakers' concerns highlight growing tensions over law enforcement's use of controversial hacking tools.

WhatsApp Exposes Italian Users to Spyware via Fake iOS App
WhatsApp has alerted around 200 users, mostly in Italy, about a sneaky spyware attack that hit them after they downloaded a fake version of the app for iOS. This alarming incident raises a crucial question: how can you trust that the app on your phone is genuine?

PlushDaemon Exclusive: Dangerous New Spy Malware
Exclusive: PlushDaemon malware is a stealthy new spy quietly siphoning personal data — learn how it works, whos at risk, and easy steps you can take to protect yourself.

Chinese-Linked Hackers Stunning Windows Spy Damages Envoys
Chinese-linked UNC6384 is exploiting a Windows vulnerability to plant stealthy spyware in diplomatic and commercial networks—an unsettling upgrade in tradecraft that challenges whether governments, companies, and users can patch porous defenses before quiet probes turn into loud alarms.

Apple Security Bounty: Stunning $2M Boost, Risky Win
Apple just put a price on silence — offering up to $2M (and over $5M with bonuses) for zero‑click exploits to lure researchers into legal disclosure, undercut mercenary spyware markets, and speed fixes that better protect users.

ClayRat spyware: Exclusive Risky Android Threat
Imagine a trusted Telegram app secretly scanning your messages, recording calls and sending everything off-device — that’s exactly what the new ClayRat spyware campaign is doing by spreading fake Android APKs through Telegram channels. Avoid sideloading, tighten app permissions, and treat APK links with suspicion to stop your phone from becoming a surveillance tool.

commercial spyware firms: Risky EU Ties Exposed
European MPs are demanding answers after investigations showed EU research grants and procurement money have flowed — sometimes via subcontractors — to companies tied to commercial spyware, raising urgent questions about whether public funds are enabling surveillance of journalists, activists and political rivals. Europe must reconcile its push for tech sovereignty with stronger transparency, vetting and clawback rules to ensure funding defends, not undermines, democracy.

targeted spy attacks: Stunning, Dangerous iPhone 8 Risk
Apple rushed a rare backport to iPhone 8 and some iPads after a recently patched zero‑day appears to have been used in highly sophisticated, targeted spy attacks — a reminder that even older phones can be weaponized and updates matter.

CVE-2025-43300 Must-Have Patch — Critical Security Risk
Apple has backported a fix for CVE-2025-43300 — a high‑severity ImageIO flaw actively exploited in the wild — so update now to block image‑based attacks that can crash or hijack your device. If you can’t upgrade, install Apple’s backported updates for older iOS, iPadOS and macOS builds and be extra cautious opening unexpected images.

Android zero-day Critical Emergency: Must-Have Fix
Samsung just pushed an emergency patch for a critical Android zero‑day that’s been actively exploited — install it now to stop attackers from reading messages, using your mic, or tracking your device. Even after updating, enable automatic updates and avoid installing apps from untrusted sources to stay safer.

spyware campaign Exclusive Critical Alert for France
Apple quietly warned some French iCloud users they may have been targeted by sophisticated spyware, and CERT-FR confirmed this is the fourth such alert in 2025—suggesting a focused campaign rather than a mass outbreak. If you saw the Apple Security notice, update your devices, review account access and authentication, and consider expert help to secure sensitive communications.