Huntress says a researcher targeted after Black Hat and Def Con was sent a Google Doc that rendered an Apps Script sidebar with ClickFix instructions. The lure arrived by DM, not email.
Publishers:infosecurity-magazine.com · scworld.com
Reality
- Evidence68
- Adoption34
- Hype gap+14
- Incentives62
- Confidence66
Sophos X-Ops confirmed 38 AI-related MDR cases across twelve months. Impersonation of AI software accounted for 30 of them, and conventional payload controls were what stopped them.
Publishers:nakedsecurity.sophos.com
Reality
- Evidence62
- Adoption54
build1 distinct publisher Jamf Threat Labs describes a Rust stealer that copies Chromium profiles and drives them over Chrome DevTools Protocol. Password rotation does not revoke what it exports.
Publishers:dev.to
Reality
- Evidence64
- Adoption18
Sophos says a June 2026 campaign used winget to install the Deno runtime on victim machines, then used deno.exe to fetch, run and persist remote JavaScript ending in a Python infostealer.
Publishers:nakedsecurity.sophos.com
Reality
- Evidence70
- Adoption63
Attackers installed a legitimate JavaScript and TypeScript runtime on victim hosts to run payloads in memory. The middle of the chain barely varied, which is where detection work belongs.
Publishers:nakedsecurity.sophos.com
Reality
- Evidence62
- Adoption41