Malicious AI-generated npm package hits Solana users

6 months ago

AI-generated npm package @kodane/patch-manager drained Solana wallets; 1,500+ downloads before takedown on July 28, 2025. AI-generated npm package @kodane/patch-manager was…

Meta Offers $1M bounty at Pwn2Own Ireland 2025 for WhatsApp exploits

6 months ago

Meta backs Pwn2Own Ireland 2025 in Cork, offering up to $1M for WhatsApp exploits; targets include phones and wearables, Oct…

ToolShell under siege: Check Point analyzes Chinese APT Storm-2603

6 months ago

Storm-2603 group exploits SharePoint flaws and uses a custom C2 framework, AK47 C2, with HTTP- and DNS-based variants named AK47HTTP…

CISA released Thorium platform to support malware and forensic analysis

6 months ago

CISA releases Thorium, an open-source tool for malware and forensic analysis, now available to analysts in government, public, and private…

Russia-linked APT Secret Blizzard targets foreign embassies in Moscow with ApolloShadow malware

6 months ago

Russia-linked Secret Blizzard targets foreign embassies in Moscow via ISP-level AitM attacks, deploying custom ApolloShadow malware. Microsoft researchers uncovered a…

Attackers actively exploit critical zero-day in Alone WordPress Theme

6 months ago

Hackers exploit a critical vulnerability, tracked as CVE-2025-5394 (CVSS score of 9.8), in the Alone WordPress theme to hijack sites.…

Dahua Camera flaws allow remote hacking. Update firmware now

7 months ago

Critical flaws in Dahua cameras let hackers take control remotely. The vendor has released patches, users should update firmware asap.…

Researchers released a decryptor for the FunkSec ransomware

7 months ago

Researchers have released a decryptor for the ransomware FunkSec, allowing victims to recover their encrypted files for free. Researchers at…

Apple fixed a zero-day exploited in attacks against Google Chrome users

7 months ago

Apple addressed a high-severity vulnerability that has been exploited in zero-day attacks targeting Google Chrome users. Apple released security updates…

PyPI maintainers alert users to email verification phishing attack

7 months ago

PyPI warns of phishing emails from noreply@pypj[.]org posing as "[PyPI] Email verification" to redirect users to fake package sites. PyPI…

This website uses cookies.