AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads

2 weeks ago

AsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities. OX Security researchers…

U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog

2 weeks ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog. The U.S.…

SonicWall warns of active exploitation of two SMA 1000 zero-days

2 weeks ago

SonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution. SonicWall confirmed the…

Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one month

2 weeks ago

Patch Tuesday: Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and…

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

2 weeks ago

U.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical…

Attacker Used AI to Build Custom PowerShell Recon Malware

2 weeks ago

Huntress found an AI-generated PowerShell script used for AD reconnaissance, showing attackers are using AI to create custom, evasive tools.…

Malware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily Suspended

2 weeks ago

Japan's largest taxi operator Nihon Kotsu shut down systems after a malware attack, disrupting dispatch and bookings. Nihon Kotsu, Japan's…

CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper

2 weeks ago

New macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf…

Lidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data Breach

2 weeks ago

Lidl disclosed a third-party data breach affecting online shop customers in Germany, Belgium, and the Netherlands. Payment data was not…

U.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog

2 weeks ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S.…

This website uses cookies.