COLDCARD security audit phishing attack installs remote access tool

2026-08-05T19:23:21Z36743772c10d07201e0a8497ffe4ed29d203220a90f850b7b34387a0ae295c4a
APT29Adversary-in-the-MiddleApache-TomcatCISAChainDropClickFixDOUBLECUPLangflowMicrosoft-365Midnight-BlizzardN-centralOpen-VSXScreenConnectTP-Link-OmadaXCSSETactive-exploitationcredential-theftdevice-code-phishinginfostealermacOS-malwarenpmpasskeysphishingremote-access-trojansupply-chain-attack

What happened

A BleepingComputer security-news feed highlights active and emerging threats, including phishing campaigns delivering remote-access malware, actively exploited enterprise vulnerabilities, supply-chain compromises, malicious developer extensions and packages, macOS malware, credential theft targeting Microsoft 365 and passkeys, and malware delivered through ClickFix and fake software installers. The feed includes high-impact incidents such as ChainDrop compromising more than 1,300 npm packages and campaigns attributed to APT29/Midnight Blizzard.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
36743772c10d07201e0a8497ffe4ed29d203220a90f850b7b34387a0ae295c4a
Enrichment time
2026-08-05T19:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.