Pass-ta-key Attack Lets Malware Hijack Google Passkeys
Unit 42 showed how malware on Chrome for Windows can abuse synced Google passkeys. Learn who is affected, what was fixed, and how to recover safely.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 4, 2026
Unit 42 showed how malware on Chrome for Windows can abuse synced Google passkeys. Learn who is affected, what was fixed, and how to recover safely.
A compromised Adform tracking script could replace Bitcoin, Ethereum, and Tron recipient addresses while an affected page was open. Check transfers and clear browser…
Crypto.com warns of targeted phishing emails about unfamiliar activity and fake bank-account changes. Check the Anti-Phishing Code, verify safely, and recover by exposure stage.
XCSSET v40 runs through trojanized Xcode projects and adds fileless persistence, browser theft, and defense evasion. Learn the build trigger, exposure boundary, and safe…
A Copilot for Word test showed a hidden instruction copying itself into generated documents. Here is the real trigger, what the research proves, and…
SvcHostUpdate.exe in Windows Startup matches a malicious web3-token-helper chain. Learn what the file proves, what to preserve, how to clean the PC, and which…
Cisco says attackers are exploiting a static credential in on-premises Secure FMC. Check for /var/tmp/license.tmp, install the release-specific hotfix, and rotate credentials, keys, and…
Six prerelease versions of @joyfill/components and @joyfill/layouts carried an import-time RAT and credential stealer. Check lockfiles, isolate affected hosts, and rotate exposed secrets.
A network of more than 120 lookalike Walmart stores uses cloned catalogs, extreme liquor discounts, and a checkout that asks for the full card…