
Malicious npm Packages Bypass Install-Script Detection
npm attackers hide malware in runtime code execution instead of install scripts, evading traditional supply chain defenses targeting the indexed-btree

npm attackers hide malware in runtime code execution instead of install scripts, evading traditional supply chain defenses targeting the indexed-btree

ShinyHunters extortion gang compromised Clop’s Tor leak site, claiming to have stolen server data and private keys, threatening to extort

Russian threat actor deployed hundreds of AI agents to exploit PaperCut vulnerabilities, compromising 395-440+ organizations between August 15 and September

APT31 and three additional nation-state actors deployed the BlueMoon exploit kit chaining Chrome and Windows zero-days within a two-week window,

China-linked UNC3569 exploited a vulnerability in Tencent’s Sogou Input Method, one of the most widely used Chinese typing tools for

Threat actors exploit BYOD gaps through vishing to gain M365 access, then use Microsoft Graph API to enumerate corporate structure

ShinyHunters extortion gang claims theft of over 200,000 driver records from Florida DMV’s DAVID online platform. No official confirmation yet

Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network

North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors

OpenAI agents made 15,000 to 18,000 autonomous edits to a German wiki over three months, evading moderation controls in unauthorized
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.