Skip to content
Hawkeye Cybersecurity
Menu
  • Home
  • Services
  • About Us
  • Cybersecurity News
  • Contact

Category: Apps

Home » Apps » Page 14
Apps

Windows Secure Boot Certificate Expired — Billions of PCs Affected Including Linux Distros

The clock has run out. As of June 24, 2026, the first of Microsoft’s original Secure Boot certificates, the Microsoft Corporation KEK CA 2011, has officially expired, with the Microsoft UEFI CA …

Apps

25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally Patched

A critical security flaw lurking in curl for over 25 years has been patched, as part of a record-breaking security release that fixed 18 CVEs, the most ever issued in …

Apps

LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials

LokiBot, one of the oldest credential-stealing malware families still active today, has resurfaced in a new multi-stage campaign designed to steal credentials from a wide range of applications. The campaign …

Apps

Shai-Hulud Payload Steals GitHub, npm, Cloud, CI/CD, and SSH Credentials From Developers

A new wave of malicious npm packages is targeting developers who work with cloud and serverless infrastructure. The threat, known as the Shai-Hulud payload carrying the Hades malware family, has …

Apps

Anthropic Accuses Alibaba of ‘Illicitly’ Accessing Its Claude AI Models in Largest Known Distillation Attack

Anthropic has formally accused Chinese tech and e-commerce giant Alibaba of orchestrating a massive, unauthorized extraction campaign targeting its Claude AI model, marking what the company describes as the largest …

Apps

Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection

A new and stealthy backdoor named Mistic has been quietly targeting corporate networks since April 2026, disguising itself using the names and appearance of legitimate Microsoft endpoint security components. This …

Apps

Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse

Threat actors are once again exploiting the trust people place in everyday workplace tools. A newly discovered phishing campaign is using fake Microsoft Teams notifications to trick employees into downloading …

Apps

Fake Document Reader in The Google Play Store with 100K Downloads Deliver Android Malware

A dangerous Android banking trojan is once again spreading through the Google Play Store, hiding inside what appears to be a simple document reader app. The app has already been …

Apps

Malicious Edge Extension Uses Chrome Native Messaging to Execute Code on Victim Systems

A new and deceptive malware campaign has been uncovered, one that turns an everyday browser extension into a dangerous tool for system compromise. Security researchers have identified a threat that …

Apps

EvilTokens Hides Its Attack Flow in the Browser, Exposing Static Analysis Gaps  

 EvilTokens is drawing attention in phishing investigations for abusing Microsoft Device Code authentication and hiding key parts of its attack flow from static URL analysis.    In a recent analysis, the phishing page was …

Posts navigation

Older posts
Newer posts

Recent Posts

  • Anthropic Launches Claude Security Plugin to Scan Code for Vulnerabilities
  • RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
  • Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
  • ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
  • A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026

Categories

  • Apps
Let's Connect!
Copyright © 2026 Hawkeye Cybersecurity. Veteran Owned and Operated.