
Session-cookie theft: infostealers drained paid Claude accounts without touching a password
Anthropic says commodity infostealers lifted live Claude session cookies off user machines and replayed them to burn paid usage, bypassing 2FA entirely.

Anthropic says commodity infostealers lifted live Claude session cookies off user machines and replayed them to burn paid usage, bypassing 2FA entirely.

A worm hijacked Red Hat's npm namespace, a rootkit spread through 1,500 Arch AUR packages, and a SOC 2-certified AI gateway shipped malware. Registries are under fire.

McAfee says a free malware-as-a-service stealer called WeedHack has hit 116,000+ Minecraft systems via fake mods and cheats. Here's what it grabs and how to clean up.

Kaspersky pinned a supply-chain attack on the DAEMON Tools installer dating to April 8. Thousands hit globally, dozens upgraded to a QUIC RAT implant via signed binaries.

Aikido found a stage-2 Go binary inside two health-check-themed packages that runs an OpenAI-compatible router routing Claude, GPT, and Gemini traffic through Chinese aggregators.