A massive npm supply chain compromise forced CISA and GitHub to take urgent action. A worm named Shai-Hulud spread through developer tools and infected packages, harvesting credentials and replicating itself across the JavaScript ecosystem. This breach shows how fragile open source supply chains can be. The Shai-Hulud Worm Researchers found Shai-Hulud embedded in npm packages.…
The BrickStorm espionage campaign has raised alarm in the cybersecurity community. Linked to Chinese threat actors, the operation focuses on law firms and legal technology companies. By stealing case files, contracts, and intellectual property, BrickStorm highlights how vulnerable the legal sector has become. What Is BrickStorm? Security researchers describe BrickStorm as a long-running espionage campaign.…
A hacker arrested after a cyberattack on European airports is now facing investigation. Authorities believe the suspect carried out disruptions that targeted critical systems across major travel hubs. This incident highlights the growing risks airports face from cybercrime. The Arrest Law enforcement confirmed the arrest of a hacker tied to a recent wave of attacks.…
Supermicro BMC flaws have raised concerns across the security industry. Researchers discovered vulnerabilities in Supermicro’s Baseboard Management Controllers (BMCs) that attackers could exploit to install persistent backdoors. These flaws create long-term risks for organizations relying on Supermicro servers. What Are BMCs? Baseboard Management Controllers are dedicated chips on server motherboards. They allow administrators to monitor…
The NYC telecom threat dismantled by the U.S. Secret Service highlights how close attackers came to crippling communications in New York. Agents uncovered a sprawling SIM farm network hidden across multiple sites, designed to interfere with critical infrastructure. Authorities seized more than 300 SIM server boxes and 100,000 SIM cards within a 35-mile radius of…
Cybercriminals have launched a disturbing campaign against Swiss citizens, sending fake death threat emails designed to frighten people into paying ransom. The emails claim to come from a hired assassin who promises to spare the victim’s life in exchange for money. The scam relies on emotional pressure rather than technical hacking. By weaponizing fear, attackers…
The GrammaTech ransomware attack claims have raised serious concern. Play ransomware operators listed the U.S. cybersecurity firm on their dark web portal and asserted they stole sensitive company data. GrammaTech works with government agencies including DARPA, NASA, and U.S. defense institutions. Its expertise in software analysis and vulnerability research makes it an attractive target for…
American Archive of Public Broadcasting bug exposed restricted media for years. A flaw let users bypass controls and download private content. Researchers reported the issue, and the archive patched it quickly. The Vulnerability The flaw came from insecure direct object references. Users could change media ID parameters and access files that should have stayed private.…
LastPass warns that attackers infect Mac users with malware by using fake password managers. These malicious apps mimic trusted software and spread via misleading GitHub repositories. Mac users who install them may face serious data theft. Overview of the Attack Campaign Attackers set up fake apps that impersonate legitimate software, then host them in GitHub…