N.Korea-linked PolinRider campaign spread malware via open-source software
The campaign has published 108 fake packages and extensions across popular platforms including npm, Packagist, Go, and Google Chrome.
The campaign has published 108 fake packages and extensions across popular platforms including npm, Packagist, Go, and Google Chrome.
Researchers believe ARToken is closely linked to the EvilTokens phishing platform.
In brief: CISA flags a SharePoint flaw as actively exploited, Google and partners take action against the NetNut residential proxy network, and more.
US authorities say that Peter Stokes helped carry out cyberattacks that targeted several major companies.
The suspect allegedly carried out large-scale cyberattacks targeting more than 150 US universities stealing academic research and data.
Attackers published at least eight fake Pyrogram packages that included the original code along with a hidden backdoor.
The campaigns leveraged a new malware toolkit that includes SHARDLOADER, MINIRECON, and ZOHOMURK.
New Microsoft’s research shows that AI agents can be tricked into sharing sensitive information without breaking any rules.
The attack affects AI browsers and assistants that can perform actions on a user's behalf, such as clicking links, filling out forms, and accessing signed-in accounts.
UNC5792 is associated with the FSB Border Guards, while UNC4221 is believed to operate on behalf of the Russian military.
Showing elements 131 - 140