Visualização normal

Antes de ontemStream principal

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

21 de Agosto de 2026, 20:00

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls

The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.

  • ✇Cybersecurity News
  • ChainDrop npm Worm Hits 400+ Packages via Blockchain C2 Do Son
    ChainDrop npm worm infected 400+ packages, stealing cloud keys and CI secrets via blockchain C2. Unit 42 details the full attack chain and fixes. Related Posts: Fake Zoom Installer Drops Overlord RAT on macOS macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate Fake AI Tools Malware Targets Developers Through GitHub The post ChainDrop npm Worm Hits 400+ Packages via Blockchain C2 appeared first on Daily CyberSecurity.
     
  • ✇Unit 42
  • ChainDrop: Inside a Self-Propagating npm Worm Unit 42
    Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
     

ChainDrop: Inside a Self-Propagating npm Worm

6 de Agosto de 2026, 19:26

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.

The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

❌
❌