Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069

Google has formally attributed the supply chain compromise of the popular Axios npm package to a financially motivated North Korean threat activity cluster tracked as UNC1069.
“We have attributed the attack to a suspected North Korean threat actor we t… Continue reading Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069

Posted in Uncategorized

Android Developer Verification Rollout Begins Ahead of September Enforcement

Google on Monday said it’s officially rolling out Android developer verification to all developers to combat the problem of bad actors distributing harmful apps while “hiding behind anonymity.”
The development comes ahead of a planned verification mand… Continue reading Android Developer Verification Rollout Begins Ahead of September Enforcement

Posted in Uncategorized

TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks

A high-severity security flaw in the TrueConf client video conferencing software has been exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia dubbed TrueChaos.
The vulnerability in question is CVE-2… Continue reading TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks

Posted in Uncategorized

The AI Arms Race – Why Unified Exposure Management Is Becoming a Boardroom Priority

The cybersecurity landscape is accelerating at an unprecedented rate. What is emerging is not simply a rise in the number of vulnerabilities or tools, but a dramatic increase in speed. Speed of attack, speed of exploitation, and speed of change across … Continue reading The AI Arms Race – Why Unified Exposure Management Is Becoming a Boardroom Priority

Posted in Uncategorized

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

The popular HTTP client known as Axios has suffered a supply chain attack after two newly published versions of the npm package introduced a malicious dependency.
Versions 1.14.1 and 0.30.4 of Axios have been found to inject “plain-crypto-js” version 4… Continue reading Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

Posted in Uncategorized

OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new findings from Check Point.
“A single malicious prompt could turn an otherwise ordinary conver… Continue reading OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

Posted in Uncategorized

DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials

A new campaign has leveraged the ClickFix social engineering tactic as a way to distribute a previously undocumented malware loader referred to as DeepLoad.
“It likely uses AI-assisted obfuscation and process injection to evade static scanning, while c… Continue reading DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials

Posted in Uncategorized