Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Over 250 domains linked to the ClickFix macOS malware now use browser fingerprinting to hide payloads from security tools. The campaign selectively serves malicious downloads to Mac users while blocking crawlers and sandboxes.
A Canadian hacker admitted to exploiting Snowflake customer accounts, compromising data of over 100 million individuals across 165 organizations. He faces charges including computer fraud and aggravated identity theft.
New techniques allow less-skilled attackers to exploit AI tools, shifting traditional threat models. Security teams must now account for 'vibe hacking' tactics that bypass conventional defenses.
Attackers use fake software updates to install ScreenConnect for persistent remote access. Security teams should monitor for unauthorized RMM deployments.
A malicious npm worm originating from keyv@6.0.0 has infected hundreds of packages, stealing credentials and embedding backdoors. Security firms report widespread contamination across the npm ecosystem.
The Greatness phishing-as-a-service platform now leverages OAuth 2.0 device code flows to steal tokens and circumvent multi-factor authentication. This adds to the growing trend of adversary-in-the-middle attacks targeting enterprise credentials.
A supply chain attack targeting QuickFox VPN has been delivering the FDMTP backdoor since August 2025. Security teams should review third-party dependencies and distribution channels.
A roundup of critical web app security threats including rogue AI models, major cryptocurrency theft, and infrastructure misconfigurations. Teams must audit permissions and dependencies immediately.
The INC ransomware group is now the top threat exploiting known flaws in SonicWall's SMA 1000 VPN devices. Multiple organizations have been compromised and listed on the group's leak site.
New research reveals critical vulnerabilities in Chrome's Google Password Manager that could allow malware to bypass passkey authentication entirely. Attackers can gain access without requiring any user interaction or biometric verification.