Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal…
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal…
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome us…
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 a…
Analisis profundos, perfiles de amenaza e informes sectoriales.
Verfijnde threat intelligence-publicatie met context, observaties en duiding voor teams die gericht en met rust willen…
Leer informe
Miasma is a fast-moving software supply-chain worm targeting npm packages, CI/CD pipelines, developer environments, and…
Leer informe
Tycoon2FA device-code phishing represents a shift in how attackers target Microsoft 365 environments. Instead of relyin…
Leer informe
Binnen Amuneth Watch zien we dagelijks een groot aantal malware-alerts met namen als Wacatac, Bearfoos, TurtleLoader en…
Leer informe