Visualização normal

Antes de ontemSecurity Boulevard
  • ✇Security Boulevard
  • Coding Agents Widen Your Supply Chain Attack Surface  Saqib Jan
    Software supply chain attacks are evolving. Beyond compromised packages, discover the 2026 "Agentic" threat surface—where prompt injection, toolchain poisoning, and hallucinated dependencies bypass traditional DevSecOps. Learn how the 3 Pillars and AI-driven sandboxing provide a new defensive architecture. The post Coding Agents Widen Your Supply Chain Attack Surface  appeared first on Security Boulevard.
     
  • ✇Security Boulevard
  • CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive Tom Abai
    On March 20, 2026 at 20:45 UTC, Aikido Security detected an unusual pattern across the npm registry: dozens of packages from multiple organizations were receiving unauthorized patch updates, all containing the same hidden malicious code. What they had caught was CanisterWorm, a self-spreading npm worm deployed by the threat actor group TeamPCP. We track this […] The post CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive appeared first on Security Boulevar
     

CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive

21 de Março de 2026, 17:37

On March 20, 2026 at 20:45 UTC, Aikido Security detected an unusual pattern across the npm registry: dozens of packages from multiple organizations were receiving unauthorized patch updates, all containing the same hidden malicious code. What they had caught was CanisterWorm, a self-spreading npm worm deployed by the threat actor group TeamPCP. We track this […]

The post CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive appeared first on Security Boulevard.

❌
❌