Lampion Banking Trojan Evolves with ClickFix Social Engineering: A Comprehensive Threat Analysis

Security researchers have uncovered a sophisticated evolution of the Lampion banking trojan campaign, marking a significant escalation in cyber threats targeting Portuguese-speaking financial institutions. This long-running operation, active since at least 2019, has undergone substantial tactical refinements, incorporating the rapidly emerging ClickFix social engineering technique that has proven devastatingly effective across the global threat landscape.

Read More

The New Frontier: AI meets Ransomware

The cybersecurity landscape has entered an inflection point. Where traditional ransomware once involved attacker-coded payloads and direct encryption demands, modern campaigns are now increasingly driven by artificial intelligence: self-learning, adaptive, tailored, and increasingly difficult to detect or defend against. According to recent research, as much as 80 % of ransomware attacks now utilise artificial intelligence.

Read More

YouTube Ghost Network: How Cybercriminals Weaponized 3,000+ Videos to Distribute Malware

A sophisticated malware distribution campaign has transformed YouTube into an unexpected threat vector, leveraging over 3,000 compromised videos to deliver information-stealing malware to unsuspecting users. This operation, designated as the “YouTube Ghost Network” by Check Point Research, represents a paradigm shift in how threat actors exploit trusted platforms to achieve large-scale compromise.

Read More

The Hidden Danger in AI Browsers: How PromptFix and Screenshot Attacks Are Redefining Cybersecurity Threats

The rise of AI-powered browsers has introduced a new frontier in web security—one where traditional defenses fall short and attackers have found innovative ways to exploit artificial intelligence itself. Recent research has uncovered critical vulnerabilities in agentic AI browsers, particularly Perplexity’s Comet browser, revealing how malicious actors can manipulate these tools through sophisticated prompt injection techniques.

Read More

Critical Security Alert: Over 250 Magento Stores Compromised in 24 Hours Through Adobe Commerce Vulnerability

A coordinated cyberattack has successfully compromised more than 250 Adobe Commerce and Magento Open Source e-commerce stores within a 24-hour period, exploiting a recently disclosed critical vulnerability. E-commerce security firm Sansec has issued an urgent warning as threat actors actively leverage CVE-2025-54236, also known as “SessionReaper,” to hijack customer accounts and deploy malicious backdoors across vulnerable platforms.

Read More