COLDCARD security audit phishing attack installs remote access tool
2026-08-05T19:23:21Z•36743772c10d07201e0a8497ffe4ed29d203220a90f850b7b34387a0ae295c4a
APT29Adversary-in-the-MiddleApache-TomcatCISAChainDropClickFixDOUBLECUPLangflowMicrosoft-365Midnight-BlizzardN-centralOpen-VSXScreenConnectTP-Link-OmadaXCSSETactive-exploitationcredential-theftdevice-code-phishinginfostealermacOS-malwarenpmpasskeysphishingremote-access-trojansupply-chain-attack
What happened
A BleepingComputer security-news feed highlights active and emerging threats, including phishing campaigns delivering remote-access malware, actively exploited enterprise vulnerabilities, supply-chain compromises, malicious developer extensions and packages, macOS malware, credential theft targeting Microsoft 365 and passkeys, and malware delivered through ClickFix and fake software installers. The feed includes high-impact incidents such as ChainDrop compromising more than 1,300 npm packages and campaigns attributed to APT29/Midnight Blizzard.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 36743772c10d07201e0a8497ffe4ed29d203220a90f850b7b34387a0ae295c4a
- Enrichment time
- 2026-08-05T19:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.