Google says the BlackFile crew has targeted dozens of organisations by phoning staff and posing as internal IT. No vendor bug is involved, which puts the remedy on IT leadership.
Publishers:cloud.google.com
Reality
- Evidence70
- Adoption42
- Hype gap+8
- Incentives62
- Confidence58
build1 distinct publisher RuntimeWire says it drove an agent thread in Cursor Desktop from a terminal using a gated feature that appears in neither the CLI guide nor the changelog.
Publishers:runtimewire.com
Reality
- Evidence66
- Adoption14
build1 distinct publisher A dev.to writeup shows ANTHROPIC_BASE_URL set in a terminal does not reach the VS Code extension's agent process, which inherits the editor's environment instead.
Publishers:dev.to
Reality
- Evidence46
- Adoption
- Insufficient
- Hype gap
Sophos says a June 2026 campaign used winget to install the Deno runtime on victim machines, then used deno.exe to fetch, run and persist remote JavaScript ending in a Python infostealer.
Publishers:nakedsecurity.sophos.com
Reality
- Evidence70
- Adoption63
Attackers installed a legitimate JavaScript and TypeScript runtime on victim hosts to run payloads in memory. The middle of the chain barely varied, which is where detection work belongs.
Publishers:nakedsecurity.sophos.com
Reality
- Evidence62
- Adoption41