Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal…
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal…
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome us…
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 a…
Analyses approfondies, profils de menace et rapports sectoriels.
Verfijnde threat intelligence-publicatie met context, observaties en duiding voor teams die gericht en met rust willen…
Lire le rapport
Miasma is a fast-moving software supply-chain worm targeting npm packages, CI/CD pipelines, developer environments, and…
Lire le rapport
Tycoon2FA device-code phishing represents a shift in how attackers target Microsoft 365 environments. Instead of relyin…
Lire le rapport
Binnen Amuneth Watch zien we dagelijks een groot aantal malware-alerts met namen als Wacatac, Bearfoos, TurtleLoader en…
Lire le rapport