ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
ID: e6fb28ba-9f61-5b9e-8aff-c9f4d9c1ce62
STIX ID: report--e6fb28ba-9f61-5b9e-8aff-c9f4d9c1ce62
Feed Name: The Hacker News
### Executive summary A ThreatsDay bulletin (23 Jul 2026) describing numerous active threats and security changes: supply-chain droppers distributed via npm and possibly PyPI, a macOS AMOS-family infostealer, a VS Code marketplace extension acting as a backdoor with millions of downloads, phishing campaigns delivering Lampion banking malware and SectopRAT via malicious Claude artifacts, Android surveillance/ad-fraud apps, TrickBot using DNS tunneling for C2, AI-code and guardrail abuse techniques, and Iranian-affiliated activity targeting PLCs/OT — illustrating widespread attacker use of trusted channels and legitimate features to scale espionage, fraud, and data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
