
Microsoft: 14 npm Packages Linked to Single Actor Stealing AWS Keys
Microsoft attributed 14 malicious npm packages impersonating OpenSearch and Elasticsearch to a single threat actor who stole AWS credentials and

Microsoft attributed 14 malicious npm packages impersonating OpenSearch and Elasticsearch to a single threat actor who stole AWS credentials and

Play ransomware listed six victims on May 25, led by consumer brand MyPillow and a US telecom provider, in a

Incransom claimed two US victims on May 25 — Open Door Health Center in Illinois and manufacturer PILLER AIMMCO —

Incransom has claimed a full-network breach of Meirc Training & Consulting on May 25, threatening to publish 1TB of employee

Nova ransomware claimed Brazil’s SECONT and Turkey’s Adensa Teknoloji on May 24, its third posting in three days spanning South

Qilin ransomware disclosed seven victims in a single May 24 batch across five countries, including a Czech financial firm and

Nightspire ransomware posted nine victims on May 24 including US adult day center La Familia, an Egyptian Papa John’s franchise,

ShinyHunters listed Charter Communications with 42 million claimed records and a May 27 dump deadline; Charter confirmed an investigation with

Baker Distributing Company was added to ShinyHunters’ Salesforce extortion campaign with 260,000 CRM records exposed and a May 27 public

Security researcher Louis found that Trump Mobile’s HTTP POST API returned 27,000 customer records without any authorization check during the
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.