Cybersecurity researchers have discovered a new information-stealing malware named PupkinStealer. The malware, first identified in April 2025, steals browser credentials, messaging app sessions, and desktop files, and sends the data via Telegram’s Bot API. Despite its simplicity and use of legitimate platforms, it poses a noteworthy threat due to its effectiveness and lack of sophisticated features that would typically trigger security solutions.

M&S shoppers urged to follow 'simple rule' after cyber incident – Daily Express
M&S shoppers are advised to adhere to a “simple rule” following a recent cyber incident. The guidance aims to help customers protect their personal information