A weekly security roundup points to a familiar pattern: stale endpoints, obscure payloads, and consumer devices that behave more like unmanaged computers than appliances.
A reported disruption involving NetNut points to a wider problem in cybercrime: residential proxy infrastructure turns ordinary devices into disposable cover for abuse.
A lookalike of an open-source clipboard manager is being used as a lure for a macOS infostealer that leans on native automation, local password checks, and clipboard scraping.
Fake Google and Cloudflare verification screens are being used as a trust trap, pushing victims to run commands that load a rotating mix of stealers, loaders, and remote access tools.
ClickFix lures that impersonate Google and Cloudflare turn a routine browser check into a user-driven launchpad for stealers, loaders, and remote-access malware.
A disguised Mac utility, a two-stage payload, and local password validation through PAM reveal a stealthier playbook for credential theft.
A compiled AppleScript lure, a cloned download page, and a local authentication check show how macOS trust can be turned against the user.
A newly identified Windows loader shows how operators can pair fake installers and exposed services with in-memory Beacon staging to make intrusion chains harder to spot.
A deceptive file name, compromised websites, and PowerShell show how modern infostealers can lean on trust rather than flashy exploits.
A document-themed JavaScript lure, PowerShell, and Blogspot form a delivery chain that pushes PureLog Stealer into memory, showing how familiar tools can be bent into a stealthy malware pipeline.
Google said it disrupted a residential proxy botnet used for malware control traffic and password spray attacks, with FBI, Lumen, and other partners involved.
Google, with the FBI, Lumen, and other partners, reportedly moved against NetNut, also tracked as Popa, in a case that spotlights how residential proxy infrastructure can support malware command-and-control.
The reported chain turns DLL loading behavior into an execution path, showing how a trusted Windows mechanism can be bent to stage Beacon without obvious on-disk clues.