TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
Cybersecurity researchers at OX Security have uncovered a campaign that abuses 24 npm packages as free phishing infrastructure. The packages host HTML…
unpkg is a content delivery network for npm packages. Threat actors have abused it to host malicious HTML files that render as…
Cybersecurity researchers at Trend Micro's TrendAI have uncovered a set of 14 trojanized npm packages that masquerade as legitimate calendar and streak…
Google Threat Intelligence Group attributes the axios npm compromise to MIDNIGHT NEPTUNE, formerly known as UNC1069. The actor is linked to North…
Cybersecurity researchers have uncovered a typosquatting campaign targeting RubyGems users with a Windows-based information stealer. The campaign, tracked as StubMaker by OpenSourceMalware,…
This week's ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights…
Mozilla has revoked the cryptographic signing key used for Firefox and Thunderbird downloads on Linux after an unencrypted copy of the key…
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
WEL1DROPPER is a downloader used in a campaign involving nearly 800 malicious npm packages. It identifies the host OS and architecture, then…