The attack begins with phishing emails impersonating voicemail notifications that direct victims through a multi-stage redirect chain abusing legitimate services, including Google Meet, Google Ads infrastructure, and Amazon S3, before ultimately reaching an attacker-controlled...
The attack begins with phishing emails impersonating voicemail notifications that direct victims through a multi-stage redirect chain abusing legitimate services, including Google Meet, Google Ads infrastructure, and Amazon S3, before ultimately reaching an attacker-controlled...
Multiple npm packages in the keyv/cacheable ecosystem were compromised following the compromise of a GitHub maintainer account, resulting in the publication of malicious package versions. All versions shared a consistent payload. Starting at 9:00 UTC, the attacker first used a...
Multiple npm packages in the keyv/cacheable ecosystem were compromised following the compromise of a GitHub maintainer account, resulting in the publication of malicious package versions. All versions shared a consistent payload. Starting at 9:00 UTC, the attacker first used a...
Microsoft Threat Intelligence identified CaptiveCrunch, an ongoing cyberespionage campaign conducted by Storm-2945, a subgroup of the Russian state-sponsored actor Midnight Blizzard. The campaign compromises hospitality-sector captive portal infrastructure to perform adversary...
Microsoft Threat Intelligence identified CaptiveCrunch, an ongoing cyberespionage campaign conducted by Storm-2945, a subgroup of the Russian state-sponsored actor Midnight Blizzard. The campaign compromises hospitality-sector captive portal infrastructure to perform adversary...
The observed attack chain begins with reconnaissance against the FlexPLM WSDL endpoint, followed by exploitation of the information disclosure vulnerability and CVE-2026-12569, a deserialization flaw that enables unauthenticated remote code execution. Attackers deploy hex-name...
The observed attack chain begins with reconnaissance against the FlexPLM WSDL endpoint, followed by exploitation of the information disclosure vulnerability and CVE-2026-12569, a deserialization flaw that enables unauthenticated remote code execution. Attackers deploy hex-name...
On July 18-19, 2026, an attacker compromised at least two dormant RubyGems maintainer accounts (inactive since 2019) to publish malicious gem versions. The attack was discovered when git_credential_manager appeared with suspicious behavior—downloading binaries from a public Fo...
On July 18-19, 2026, an attacker compromised at least two dormant RubyGems maintainer accounts (inactive since 2019) to publish malicious gem versions. The attack was discovered when git_credential_manager appeared with suspicious behavior—downloading binaries from a public Fo...
NadMesh uses a centralized controller to coordinate scanning across large IP ranges and attempts exploitation using more than 20 supported attack vectors. The malware targets exposed services such as Docker APIs, Kubernetes APIs, Redis, Elasticsearch, Jenkins, WebLogic, and MC...
NadMesh uses a centralized controller to coordinate scanning across large IP ranges and attempts exploitation using more than 20 supported attack vectors. The malware targets exposed services such as Docker APIs, Kubernetes APIs, Redis, Elasticsearch, Jenkins, WebLogic, and MC...
A large-scale credential theft campaign exploiting CVE-2025-54068, a critical unauthenticated remote code execution vulnerability in Laravel Livewire v3. Attackers used PHP deserialization to execute a Bash-based credential stealer that harvested sensitive application secrets ...
A large-scale credential theft campaign exploiting CVE-2025-54068, a critical unauthenticated remote code execution vulnerability in Laravel Livewire v3. Attackers used PHP deserialization to execute a Bash-based credential stealer that harvested sensitive application secrets ...
On July 14, 2026, an attacker opened 37 pull requests to the AsyncAPI generator repository. Almost all attempted to add a fake charity donation page. Camouflage in the noise, a single PR exploited a misconfigured GitHub Actions workflow to steal a highly privileged Personal Ac...
On July 14, 2026, an attacker opened 37 pull requests to the AsyncAPI generator repository. Almost all attempted to add a fake charity donation page. Camouflage in the noise, a single PR exploited a misconfigured GitHub Actions workflow to steal a highly privileged Personal Ac...
AhnLab ASEC identified an ongoing Linux-targeted cryptomining campaign that compromises internet-exposed SSH servers using brute-force attacks against weak credentials. Once access is obtained, attackers deploy a multi-stage malware toolkit consisting of Go-based downloaders a...
AhnLab ASEC identified an ongoing Linux-targeted cryptomining campaign that compromises internet-exposed SSH servers using brute-force attacks against weak credentials. Once access is obtained, attackers deploy a multi-stage malware toolkit consisting of Go-based downloaders a...
A malicious version of the Jscrambler npm package, jscrambler@8.14.0, was published at 15:12 UTC on 11 July 2026. The compromised release executed a dropper via an npm preinstall hook that detected the host operating system and extracted a platform-specific native binary for W...
A malicious version of the Jscrambler npm package, jscrambler@8.14.0, was published at 15:12 UTC on 11 July 2026. The compromised release executed a dropper via an npm preinstall hook that detected the host operating system and extracted a platform-specific native binary for W...
A malicious version of the @injectivelabs/sdk-ts npm package (version 1.20.21) was briefly published to the official Injective Labs npm namespace after a contributor account was compromised. The package contained credential-stealing functionality that silently exfiltrated cryp...
A malicious version of the @injectivelabs/sdk-ts npm package (version 1.20.21) was briefly published to the official Injective Labs npm namespace after a contributor account was compromised. The package contained credential-stealing functionality that silently exfiltrated cryp...
Datadog Security Labs identified multiple coordinated campaigns abusing the GitHub API to systematically enumerate organizations, repositories, users, and software development activity at scale. The activity primarily relied on legitimate GitHub functionality, including dorman...
Datadog Security Labs identified multiple coordinated campaigns abusing the GitHub API to systematically enumerate organizations, repositories, users, and software development activity at scale. The activity primarily relied on legitimate GitHub functionality, including dorman...
Researchers identified a campaign leveraging the Realm C2 framework that has compromised thousands of Linux hosts between June 13-23, 2026, with a primary focus on a large managed Kubernetes clusters. The attackers exploited vulnerabilities in Argo Workflows and Gogs to gain i...
Researchers identified a campaign leveraging the Realm C2 framework that has compromised thousands of Linux hosts between June 13-23, 2026, with a primary focus on a large managed Kubernetes clusters. The attackers exploited vulnerabilities in Argo Workflows and Gogs to gain i...
According to investigations, the compromise began when attackers gained access to Klue backend systems and deployed code capable of harvesting OAuth tokens used by customers to integrate Klue with third-party platforms such as Salesforce, Gong, SharePoint, HubSpot, Slack, and ...
According to investigations, the compromise began when attackers gained access to Klue backend systems and deployed code capable of harvesting OAuth tokens used by customers to integrate Klue with third-party platforms such as Salesforce, Gong, SharePoint, HubSpot, Slack, and ...
On 17 June 2026, attackers compromised a maintainer account associated with the Mastra npm organization and used it to republish 116 packages over a 27-minute period. Rather than modifying Mastra’s source code directly, the threat actor injected a malicious dependency, easy-da...
On 17 June 2026, attackers compromised a maintainer account associated with the Mastra npm organization and used it to republish 116 packages over a 27-minute period. Rather than modifying Mastra’s source code directly, the threat actor injected a malicious dependency, easy-da...
According to the research, the threat actor operates an automated infrastructure that scans the internet for Fortinet devices and attempts authentication using a curated set of previously leaked or compromised credentials. Successful logins are recorded and continuously revali...
According to the research, the threat actor operates an automated infrastructure that scans the internet for Fortinet devices and attempts authentication using a curated set of previously leaked or compromised credentials. Successful logins are recorded and continuously revali...
Researchers have disclosed a software supply chain attack, dubbed "Atomic Arch," targeting orphaned packages in the Arch User Repository (AUR). Using newly created AUR accounts, an attacker adopted more than 400 abandoned packages through the legitimate maintainer-handoff mech...
Researchers have disclosed a software supply chain attack, dubbed "Atomic Arch," targeting orphaned packages in the Arch User Repository (AUR). Using newly created AUR accounts, an attacker adopted more than 400 abandoned packages through the legitimate maintainer-handoff mech...
According to public reports, the activity appears to be associated with a Scripted REST Resource endpoint (/api/now/related_list_edit/create) that was allegedly configured with requires_authentication = false, potentially allowing unauthenticated access to backend functionalit...
According to public reports, the activity appears to be associated with a Scripted REST Resource endpoint (/api/now/related_list_edit/create) that was allegedly configured with requires_authentication = false, potentially allowing unauthenticated access to backend functionalit...
TeamPCP has leveraged a compromised GitHub account to inject malicious code into at least 42 repositories and 236 branches across the Azure, Azure-Samples and Microsoft GitHub organizations. They were published between 02:36 and 03:22 UTC on 5 June 2026. As of 14:00 UTC on 5 J...
TeamPCP has leveraged a compromised GitHub account to inject malicious code into at least 42 repositories and 236 branches across the Azure, Azure-Samples and Microsoft GitHub organizations. They were published between 02:36 and 03:22 UTC on 5 June 2026. As of 14:00 UTC on 5 J...
Researchers identified an active supply chain attack affecting multiple npm packages that leverages a novel abuse of the binding.gyp build mechanism to execute malicious code during package installation. Unlike traditional npm supply chain attacks that rely on preinstall or po...
Researchers identified an active supply chain attack affecting multiple npm packages that leverages a novel abuse of the binding.gyp build mechanism to execute malicious code during package installation. Unlike traditional npm supply chain attacks that rely on preinstall or po...