Eight Packagist Packages Hid Their Backdoor in package.json
Eight Packagist packages hid Linux malware in package.json while attackers used GitHub itself as the CDN. See what defenders should change this week.
Eight Packagist packages hid Linux malware in package.json while attackers used GitHub itself as the CDN. See what defenders should change this week.
Underminr, CINEMAGOAL, and Laravel-Lang all attacked the same weak link: name-based trust in your cybersecurity stack. Here's how to fix it.
A CVSS 10.0 in LiteSpeed's cPanel plugin hands root to any tenant. Here's what to inventory, patch, and hunt before Monday.
Three big cybersecurity writeups this week show attackers ditching malware for your own admin tools. Here's what to fix before they show up.
Akamai's browser bet, fresh Chrome patches, and same-day Drupal exploits point to one shift every cybersecurity team should plan for. See where to start.
Megalodon hit 5,561 GitHub repos in six hours and zero-days now cost $20. Here's how to redesign your cybersecurity response for machine speed.
The Kimwolf arrest made headlines, but your cybersecurity exposure hasn't changed. Here's what actually reduces risk this week.
Google leaked an unfixed Chromium flaw the same week AI helped find a macOS kernel exploit. Here's how to harden before the inevitable. Read on.
First VPN got dismantled, but Showboat's SOCKS5 backdoors prove cybersecurity wins come from egress visibility, not law enforcement wins. See why.
Defender zero-days and a nine-year Linux kernel bug both handed attackers SYSTEM. See what cybersecurity teams should change this week.