HP Inc’s latest Threat Insights Report warns about the rising use of fake CAPTCHA verification tests to trick users into infecting their systems. Cybercriminals are capitalising on increasing ‘click tolerance’, with users now more willing to navigate complex sign-in procedures. HP cited campaigns where attackers created false CAPTCHAs and directed victims to malicious sites, eventually making them run a harmful PowerShell command that installed a remote access trojan.

“PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram
PupkinStealer is a C# malware that steals sensitive data, including browser credentials and desktop files, using Telegram for stealthy data exfiltration. Discovered in April 2025,