Breaking Lab srl
Fake IT Help Desk Messages Are Hitting Microsoft Teams

Attackers are impersonating IT support staff inside Microsoft Teams to trick employees into installing backdoor software. Here is what to watch for and how to stay safe.
Breaking Lab srl

Attackers are impersonating IT support staff inside Microsoft Teams to trick employees into installing backdoor software. Here is what to watch for and how to stay safe.

Two thousand compromised WordPress sites were secretly used to spread malware, control infected devices, and store stolen data. If you run a WordPress site, here is what this means for you.

Researchers found 41 sites that display a legitimate-looking URL but quietly redirect you to a malicious file. The usual checks — verified links and digital signatures — are no longer enough.

Some Geekom mini-PCs shipped with a malicious file hidden inside a network driver, capable of stealing passwords and logging keystrokes. If you own one, you need to act now.

Unit 42 researchers have detailed three attack paths that allow ordinary user-level malware on Windows to silently sign into passkey-protected accounts via Google Password Manager. The findings raise serious questions about passkeys as a silver-bullet authentication solution.

Researchers at Unit 42 have uncovered three attack paths that allow malware on a compromised Windows machine to silently abuse Google Password Manager's synced passkeys. The findings cast serious doubt on passkeys as an unbreakable authentication solution.

A sophisticated malvertising campaign called SourTrade is forcing victims' browsers to assemble Windows malware entirely in memory, bypassing traditional file-based detection. The operation has been active since late 2024, impersonating popular trading platforms to target retail investors.

This article provides four crucial steps to take if your online credentials are stolen, prompted by a recent data leak allegedly involving a popular online payment service. The advice includes changing passwords, checking for password reuse on other accounts, enabling two-factor authentication, and using a password manager. The article highlights the importance of proactive security measures to combat modern cyber threats.