Supply Chain Attack
jscrambler 8.14.0 npm Release Compromised to Drop a Rust Infostealer at Install
Another JavaScript-ecosystem SDK compromise — defender inventory work continues this week.
Understand the impact of malicious software on your digital security. Explore our guides on malware types, detection signs, and professional removal strategies to stay protected.
Supply Chain Attack
Another JavaScript-ecosystem SDK compromise — defender inventory work continues this week.
Threat Intelligence
A new destructive-plus-espionage malware family lands on defenders' desks — detection-engineering review this week.
Phishing
Two vendor-documented hospitality-sector phishing campaigns land the same week — sector-advisory work for hotel-industry defenders this week.
Cybercrime
Operation Endgame's latest phase takes out Amadey and StealC's shared infrastructure, with Europol and Microsoft reporting 326 servers actioned, 142 domains seized, and roughly 27 million stolen credentials recovered.
Nation-State Cyber Threats
Another published-research disclosure for defenders to review for indicator relevance: researchers at Genians named NarwhalRAT, a remote access trojan they attribute to a North Korean-linked cluster, and published indicators worth checking against your own telemetry.
Nation-State Cyber Threats
One backdoored authentication module, one isolated network, ten years of undetected access — a reminder that critical authentication primitives are a forever-target.
Nation-State Cyber Threats
ESET's research update reframes OceanLotus — the targeting is now inward.
Nation-State Cyber Threats
Consumer compression software remains a reliable initial-access vector in the Russia-Ukraine cyber theater.
Supply Chain Attack
Miasma's open-sourcing turns the previous day's Microsoft-repo incident into the first instance of a much broader supply-chain threat any actor can now reproduce.
Supply Chain Attack
For the second time in weeks, Microsoft packages were laced with credential stealers — this time targeting users of AI coding agents, forcing the company to pull more than 70 of its own GitHub repositories.
Supply Chain Attack
Another package-poisoning incident lands across a language registry, reinforcing the case for default-behavior reform that GitHub has now begun applying to npm.
Nation-State Cyber Threats
ReliaQuest disclosed OP-512, a previously unreported, China-linked espionage cluster that plants a custom three-web-shell framework on Microsoft IIS servers — the fourth such group to target IIS in a year. For anyone running IIS, it is a prompt to go hunting.