#sctocs
Chinese hackers have begun exploiting the newly revealed React2Shell vulnerability — showing how fast attackers move after a disclosure.
Full story: sctocs.com/chinese-hack...

#cybersecurity #infosec
Chinese Hackers Begin Exploiting The Newly Revealed React2Shell Vulnerability - SCtoCS
Chinese threat actors have started exploiting the newly disclosed React2Shell vulnerability, putting web applications at serious risk.
sctocs.com
December 7, 2025 at 5:24 PM
Intellexa leaks: Predator spyware used zero-days & ad-based delivery (Aladdin) to infect devices — even via just viewing ads!
Protect privacy & beware sophisticated spyware tactics.
📌 sctocs.com/intellexa-le...
Intellexa Leaks Expose Zero Days And Ads Based Delivery Method For Predator Spyware - SCtoCS
New Intellexa leaks uncover zero day exploits and an ads based vector used to deliver Predator spyware to targeted victims.
sctocs.com
December 5, 2025 at 7:45 PM
#MatrixPushC2 is using browser notifications for fileless, cross-platform phishing. Stay alert! 🚨
Read more: sctocs.com/matrix-push-...
#CyberSecurity #Phishing #InfoSec
Matrix Push C2 Uses Browser Notifications For Fileless And Cross Platform Phishing Attacks - SCtoCS
Matrix Push C2 abuses browser notification features to deliver fileless and cross platform phishing attacks, enabling stealthy credential theft and persistent user targeting.
sctocs.com
November 22, 2025 at 11:33 PM
#SHA1Hulud wave 2 hits 25 k+ #npm repos via preinstall credential theft!
Check your dependencies & dev credentials ASAP: sctocs.com/sha1-hulud-w...

#OpenSource #CyberSecurity
Second Sha1 Hulud Wave Impacts More Than 25,000 Repositories Through Npm Preinstall Credential Theft - SCtoCS
The second Sha1 Hulud wave has affected more than 25,000 repositories by abusing npm preinstall scripts to steal credentials, highlighting widespread supply chain risk.
sctocs.com
November 24, 2025 at 6:43 PM
Malware Warning: Silver Fox is distributing ValleyRAT in China with a fake Microsoft Teams installer using SEO poisoning to trick users into malware downloads. Protect systems by avoiding unverified download sites!
📌 sctocs.com/silver-fox-v...
Silver Fox Distributes ValleyRAT In China Through Fake Microsoft Teams Installer - SCtoCS
Silver Fox is spreading ValleyRAT malware in China by using a fake Microsoft Teams installer that tricks users into downloading malicious files.
sctocs.com
December 5, 2025 at 7:39 PM
A supply chain attack has compromised the Bitwarden CLI via a malicious npm package.

The attack exploited a GitHub Actions workflow to inject credential-stealing code targeting developer environments, including CI/CD pipelines and cloud infrastructure.

sctocs.com/bitwarden-cl...
Bitwarden CLI Breached In Ongoing Supply Chain Attack Linked To Checkmarx - SCtoCS
Bitwarden CLI compromised in an ongoing Checkmarx-linked supply chain attack, exposing risks in developer tools and software dependencies.
sctocs.com
April 25, 2026 at 10:38 AM
Malicious VS Code extension disguised as a Moltbot AI coding assistant was found installing malware on developers’ machines. Remove suspicious extensions and verify sources!

sctocs.com/fake-moltbot...
Fake Moltbot AI Coding Assistant On VS Code Marketplace Distributes Malware - SCtoCS
A fake Moltbot AI coding assistant on the VS Code Marketplace was found dropping malware, putting developers and source code at risk.
sctocs.com
January 29, 2026 at 9:18 AM
Threat actors are actively exploiting a WordPress Sneeit RCE flaw and a separate ICTBroadcast bug that fuels the Frost botnet. Update patches now!
🔗 sctocs.com/sneeit-wordp...
Sneeit WordPress RCE Exploited In The Wild, And ICTBroadcast Bug Powering Frost Botnet Attacks - SCtoCS
Sneeit WordPress RCE is being exploited in the wild, and an ICTBroadcast flaw is helping drive new Frost botnet attacks against vulnerable systems.
sctocs.com
December 8, 2025 at 5:38 PM
CERT Polska uncovers coordinated cyber attacks on 30+ wind and solar farms—highlighting growing threats to renewable energy infrastructure.
🔐 Focus on OT/ICS security and resilience!
👉 sctocs.com/cert-polska-...
CERT Polska Details Coordinated Cyber Attacks On Over 30 Wind And Solar Farms - SCtoCS
CERT Polska has detailed coordinated cyber attacks targeting more than 30 wind and solar farms, raising alarms for renewable energy security.
sctocs.com
February 1, 2026 at 6:52 AM
Over 30 flaws found in AI coding tools — attackers could steal data or execute arbitrary code using prompt injection and built-in features.
🔗 sctocs.com/ai-coding-to...
Researchers Find More Than 30 Flaws In AI Coding Tools Allowing Data Theft And RCE Attacks - SCtoCS
Researchers uncovered over thirty flaws in AI coding tools that can lead to data theft and remote code execution, putting developers at risk.
sctocs.com
December 7, 2025 at 5:31 PM
WinRAR vulnerability (CVE-2025-6218) is being actively exploited!
Hackers are using malicious RAR files to execute code on vulnerable systems. Users on WinRAR ≤7.11 should update to 7.12+ right away.
👉 sctocs.com/winrar-cve-2...
WinRAR Vulnerability CVE-2025-6218 Actively Targeted By Multiple Threat Groups - SCtoCS
WinRAR flaw CVE-2025-6218 is under active attack by several threat groups, putting users at risk of exploitation through malicious archives.
sctocs.com
December 10, 2025 at 7:15 PM
DarkSpectre browser extension campaigns exposed after impacting 8.8M users globally.
sctocs.com/darkspectre-...
DarkSpectre Browser Extension Campaigns Exposed After Affecting 8.8 Million Users Worldwide - SCtoCS
DarkSpectre browser extension campaigns are exposed after impacting 8.8 million users worldwide, highlighting major browser security risks
sctocs.com
January 1, 2026 at 7:00 PM
Hackers use Blender 3D assets to deliver StealC V2 malware.
More info: sctocs.com/blender-asse...
Hackers Use Blender 3D Assets To Spread StealC V2 Malware, Threatening Creators And Users - SCtoCS
Hackers are leveraging Blender 3D assets to deliver StealC V2 malware, putting creators and users at risk globally.
sctocs.com
November 25, 2025 at 7:17 PM
Security researchers warn that attackers are exploiting n8n automation workflows to deliver malware through phishing emails.

sctocs.com/n8n-webhooks...
N8n Webhooks Exploited Since October 2025 To Spread Malware Through Phishing Emails - SCtoCS
n8n webhooks have been abused since October 2025 to deliver malware via phishing emails, highlighting rising threats in automated workflow tools.
sctocs.com
April 15, 2026 at 7:44 PM
Axios npm package was compromised, delivering a cross-platform RAT through a malicious dependency during installation.

sctocs.com/axios-supply...
Axios Supply Chain Attack Delivers Cross-Platform RAT Through Compromised Npm Account - SCtoCS
Axios supply chain attack spreads a cross-platform RAT via a compromised npm account, putting developers and systems at risk of remote control.
sctocs.com
April 2, 2026 at 1:26 PM
New PLUGGYAPE malware campaign targeting Ukrainian Defense Forces via Signal & WhatsApp using fake charity messages.
sctocs.com/pluggyape-ma...
PLUGGYAPE Malware Uses Signal And WhatsApp To Target Ukrainian Defense Forces - SCtoCS
PLUGGYAPE malware leverages Signal and WhatsApp to target Ukrainian defense forces, highlighting evolving tactics in cyber warfare.
sctocs.com
January 15, 2026 at 9:55 PM
New Chrome layered defenses block indirect prompt injection attacks before they hit users.
🔗 sctocs.com/google-chrom...
Google Introduces Layered Chrome Defenses To Stop Indirect Prompt Injection Threats - SCtoCS
Google has added layered protections to Chrome to block indirect prompt injection threats, improving safety for AI assisted browsing.
sctocs.com
December 10, 2025 at 12:27 PM
Android malware families FvncBot, SeedSnatcher, and ClayRat now feature stronger data-theft functions like SMS interception and keylogging.
🔗 sctocs.com/android-malw...
Android Malware FvncBot, SeedSnatcher, And ClayRat Now Feature Enhanced Data Theft Capabilities - SCtoCS
FvncBot, SeedSnatcher, and ClayRat Android malware variants have added stronger data theft functions, increasing risks for mobile users.
sctocs.com
December 8, 2025 at 5:39 PM
React2Shell (CVE-2025-55182) now on CISA’s Known Exploited Vulnerabilities list after active exploitation observed. Update your systems immediately!
🔗 sctocs.com/react2shell-...
Critical React2Shell Flaw Added To CISA KEV After Active Exploitation Confirmed - SCtoCS
CISA has added the React2Shell vulnerability to its KEV list after confirming active exploitation, signaling urgent patching needs.
sctocs.com
December 7, 2025 at 5:30 PM
Researchers found 341 malicious ClawHub skills stealing data from OpenClaw users—be careful with add-ons and permissions!
👉 sctocs.com/341-maliciou...
Researchers Discover 341 Malicious ClawHub Skills Stealing Data From OpenClaw Users - SCtoCS
Researchers have identified 341 malicious ClawHub skills designed to steal data from OpenClaw users, exposing sensitive information.
sctocs.com
February 3, 2026 at 4:33 PM
UnsolicitedBooker is targeting Central Asian telecoms using LuciDoor and MarsSnake backdoors.
A serious cybersecurity threat in the region.
sctocs.com/unsolicitedb...

#CyberSecurity #ThreatIntel
UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor And MarsSnake Backdoors - SCtoCS
UnsolicitedBooker is targeting Central Asian telecom organizations using LuciDoor and MarsSnake backdoors to conduct sustained cyber espionage operations.
sctocs.com
February 24, 2026 at 8:41 PM
149 hacktivist-linked DDoS attacks have struck 110 organizations in 16 countries following the Middle East conflict.
sctocs.com/hacktivist-d...
149 Hacktivist DDoS Attacks Strike 110 Organizations Across 16 Countries Following Middle East Conflict - SCtoCS
Following Middle East tensions, 149 hacktivist DDoS attacks have targeted 110 organizations in 16 countries, disrupting services globally.
sctocs.com
March 4, 2026 at 8:20 PM
STAC6565 primarily targets Canada, with ~80% of attacks linked to Gold Blade deploying QWCrypt ransomware.
🔗 sctocs.com/stac6565-can...
STAC6565 Focuses On Canada In Most Attacks While Gold Blade Spreads QWCrypt Ransomware - SCtoCS
STAC6565 targets Canada in 80% of attacks, with Gold Blade deploying QWCrypt ransomware to compromise systems and steal data.
sctocs.com
December 10, 2025 at 12:46 PM
Alert: Researchers just recorded live sessions of hackers from Lazarus Group operating as “remote workers,” giving them stealthy insider‑level access to companies.

Details ➜ sctocs.com/lazarus-apt-...
Lazarus APT's Remote-Worker Operations Caught Live On Camera - SCtoCS
Researchers observe Lazarus APT's remote-worker scheme in real time, revealing North Korea’s persistent infiltration tactics.
sctocs.com
December 2, 2025 at 9:44 PM