A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
AdBlock blocks known crypto miners by default, but c/side found 3,500+ sites running stealth WebSocket miners in 2025. What each extension still misses.
A new ClickFix malware-as-a-service (MaaS) framework called Exvicy has been built on code lifted from a rival service, ErrTraffic.
Tech Times on MSN
Malicious JavaScript evaded VirusTotal in seven of eight e-commerce storefront attacks
Malicious JavaScript campaigns on e-commerce storefronts evaded VirusTotal in 7 of 8 cases, exposing a structural gap in signature-based scanning. Cloudflare's graph neural network caught all eight ...
UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG 5 min. Over the past year, GuidePoint’s Threat and Attack Simulation (TAS) team has ...
Malicious npm package indexed-btree impersonated sorted-btree, using nearly 2M weekly downloads to steal data and deliver payloads.
Sentire's Threat Response Unit (TRU) has uncovered a previously undocumented device-code phishing kit, dubbed "GhostCode," ...
Security researchers have uncovered a Brazilian banking-malware operation named KREMLIN that secretly installs malicious ...
FBI, BND and Japan's NPA name WaterPlum: 30,000 infected machines, 7,000 drained wallets. Spot the fake job offer and protect ...
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results