Eight Packagist Packages Hid Their Backdoor in package.json
Eight Packagist packages hid Linux malware in package.json while attackers used GitHub itself as the CDN. See what defenders should change this week.
Eight Packagist packages hid Linux malware in package.json while attackers used GitHub itself as the CDN. See what defenders should change this week.
Megalodon hit 5,561 GitHub repos in six hours and zero-days now cost $20. Here's how to redesign your cybersecurity response for machine speed.
First VPN got dismantled, but Showboat's SOCKS5 backdoors prove cybersecurity wins come from egress visibility, not law enforcement wins. See why.
TamperedChef and the npm Shai-Hulud lineage prove search results and package registries now ship malware. Here's the cybersecurity playbook that holds up.
One Odesa teenager allegedly harvested 28,000 accounts with off-the-shelf infostealers. Here's why your stack misses it, and what to fix now.
Microsoft disrupted Fox Tempest's malware-signing-as-a-service. Here's what it means for your cybersecurity trust model, and how to adjust.
A compromised VS Code extension reached 2.2M developer machines. See what the Nx Console and TeamPCP incidents demand from your cybersecurity playbook now.
Storm-2949 breached a cloud tenant with zero malware. Your EDR never saw it. See what to harden this week before the next stolen token lands.
Turla's peer-to-peer Kazuar reworking breaks the takedown model defenders relied on. Here's what your cybersecurity program needs to change. Read on.
Turla's P2P Kazuar, CI/CD pipeline attacks, and trojanized installers prove signature-driven cybersecurity is fading. See what to do next.