Russian hackers are trying to sneak infostealers onto people’s devices to grab passwords, crypto, and more.
Almost a dozen vulnerable UEFI shim bootloaders discovered and revoked.
Microsoft shipped three times more fixes than usual in its latest Patch Tuesday update.

Following a massive Europol takedown in May, the US Treasury has officially sanctioned the administrators behind First VPN, a service favored by ransomware groups to hide their tracks.

‘Gold Eagle’ scheme looks to centralize vulnerability identification and remediation for maximum efficiency.
Visited domains were being exfiltrated to a third-party server, seemingly under a Chinese actor’s control.
Greater visibility, better detection, and stronger governance over OAuth-connected applications should mitigate ShinyHunters attacks.
Russians are targeting misconfigured routers running in critical infrastructure firms.
Researchers found a new piece of macOS malware grabbing passwords, crypto data, and more.
Nihon Kotsu suffers malware attack, but there’s no evidence of data exfiltration yet.