Supply ChainInfosecurity Magazine·2 months ago

Lookalike npm Package Hides a Multi-Stage Windows RAT

JFrog researchers discovered a malicious npm package masquerading as the legitimate postcss-selector-parser library, designed to deliver a multi-stage Windows remote access trojan to developers who install it. This supply chain attack demonstrates the ongoing threat of typosquatting and package impersonation in open-source ecosystems, where attackers exploit developer trust to distribute sophisticated malware.

VulnerabilityInfosecurity Magazine·2 months ago

OpenAI Expands Daybreak to Help Defenders Patch Flaws

OpenAI has expanded its Daybreak initiative with a full GPT-5.5-Cyber release designed to assist security defenders in identifying and patching software vulnerabilities. The enhanced tool aims to support defensive security teams in their remediation efforts against software flaws.

Policy & LegalInfosecurity Magazine·2 months ago

Trump Issues Executive Order to Fast-Track Post-Quantum Migration

The Trump administration has issued an executive order mandating that all US federal agencies transition to post-quantum cryptography by 2031. This deadline establishes a concrete timeline for agencies to migrate away from current encryption standards vulnerable to future quantum computing threats.

PhishingInfosecurity Magazine·2 months ago

GTA 6 Scams Emerge as Pre-Orders Open

Cybercriminals are exploiting the launch of GTA 6 pre-orders by creating fraudulent websites that promise early access to the game in exchange for cryptocurrency payments. These scams capitalize on high demand and consumer excitement around the title's release to deceive victims into financial loss.

PhishingBitdefender Labs·2 months ago

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams

Bitdefender Labs uncovered more than 55 fake-shop campaigns operating across 12 European countries between March and May 2026, impersonating major global brands including Samsung, Nike, Adidas, ZARA, H&M, Amazon, Lidl, and SHEIN. These counterfeit storefronts lured consumers with fraudulent deals on high-value products and World Cup-themed scams, exploiting brand recognition to steal payment information and distribute counterfeit goods. The investigation highlights a coordinated e-commerce fraud operation targeting European consumers at scale.

Data BreachInfosecurity Magazine·2 months ago

Scattered Spider Teens Convicted of TfL Cyber-Attack

Two young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider operation, marking a significant enforcement action against the notorious threat group. The convictions demonstrate law enforcement's growing ability to identify and prosecute individual members of the distributed cybercriminal collective.

VulnerabilityTrail of Bits·2 months ago

Introducing Patch the Planet

Trail of Bits and OpenAI launched "Patch the Planet," a landmark initiative pairing AI frontier models like GPT-5.5-Cyber with expert security engineers to systematically harden critical open-source projects, delivering 64 pull requests and 51 issues across 19 key projects in just the first week. Unlike typical AI-generated bug floods, the program goes beyond finding vulnerabilities—providing triage, patches, and long-term infrastructure improvements, with 37 patches already merged into projects like Python, RustCrypto, cURL, and PyPI. The initiative signals a fundamental shift in security work: as AI makes bug discovery trivial, the real value now lies in confirmation

RansomwareInfosecurity Magazine·2 months ago

GentleKiller Framework Disables Victims' Security Software

ESET has identified GentleKiller, a framework distributed by the Gentlemen ransomware gang to its affiliates that specifically targets and disables endpoint detection and response (EDR) security software on victim systems. This tool represents a significant capability for ransomware operators, enabling them to neutralize defensive measures before deploying their encryption payloads.

VulnerabilityInfosecurity Magazine·2 months ago

Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips

A previously undisclosed BootROM vulnerability has been identified in Apple's A12 and A13 chips that cannot be patched due to its placement in the device's immutable firmware. The flaw is exploitable through USB, potentially allowing attackers to bypass security protections on affected devices. This unpatchable nature means the vulnerability will persist for the lifetime of devices using these chip generations.

Supply ChainInfosecurity Magazine·2 months ago

Microsoft Attributes Mastra AI Supply Chain Attack to North Korea

Microsoft security researchers have attributed a supply chain attack against Mastra to North Korean threat actor Sapphire Sleet, marking another instance of state-sponsored targeting of AI-related infrastructure. The attack demonstrates continued efforts by adversaries to compromise software supply chains as a vector for broader compromise.

Data BreachInfosecurity Magazine·2 months ago

Klue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth Tokens

A breach of business intelligence platform Klue has compromised OAuth tokens that enabled threat actors to target at least four cybersecurity firms through Salesforce integration. The incident demonstrates how supply chain vulnerabilities in third-party platforms can expose security-focused organizations to unauthorized access and credential theft.

Can Valorant brick YOUR PC? Is Vanguard safe?

PC Security Channel·45K views · 2 months ago

Can Valorant brick your PC? Vanguard sys Driver which is the anti-cheat software for Riot Games has come under scrutiny after bricking a lot of cheating devices, how much control does Valorant have?

HackTheBox - Nanocorp

IppSec·7.2K views · 2 months ago

00:00 - Introduction 01:00 - Start of nmap 05:00 - Looking at the contact form, it behaves oddly so disregarding it 07:00 - Playing with the PHP File Upload to see if we can upload PHP Files 10:00 - Using wget to download an image and see when it was uploaded to the webserver 12:30 - Looking into CVE-2025-24071, which we can create a .library-ms file that leaks NTLMv2 Hashes 17:30 - Cracking the web_svc NTLMv2 hash 19:50 - Using impacket's getTGT, then running RustHound and discovering we can take over another account via changepassword 25:00 - Using BloodyAD to add ourself to a group and then change the password 31:40 - Using WinRMexec to get a shell because Evil-WINRM doesn't support KRB+SSL Auth 36:30 - WinRM Shell returned, discovering we can write php scripts to the web directory but unfortunately this doesn't get us seimpersonate privileges 40:15 - Discovering CheckMK is running on the box, finding a privesc CVE 45:50 - Looking into the registry to discover which cached MSI is CheckMK 52:00 - Using RunasCS to switch to the web_svc user because we need an interactive login 01:04:30 - Changing the PID in the POC Script to be much lower which gets us the shell

VulnerabilityInfosecurity Magazine·2 months ago

AWS Unveils 'Continuum,' an AI-Powered Vulnerability Management Platform

AWS has introduced Continuum, an AI-powered platform designed to streamline the vulnerability management lifecycle by leveraging frontier AI models. The platform assists security teams across the key stages of vulnerability handling—discovery, prioritization, validation, and remediation—to improve efficiency in addressing code vulnerabilities.

OtherInfosecurity Magazine·2 months ago

Confidence Lacks in Threat Detection Across Non-Email Channels like Slack and Teams

Half of cybersecurity leaders report lacking confidence in their ability to detect threats across non-email communication platforms such as Slack and Teams, even as attackers increasingly target these channels. The finding highlights a significant gap between where modern threats are emerging and organizations' current detection and monitoring capabilities outside traditional email infrastructure. This confidence deficit suggests many security teams may be unprepared to identify compromises occurring through widely-adopted collaboration tools.

Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026

NetworkChuck·19K views · 2 months ago

Join us for our 90 minute Sumer of CCNA session, today at 5PM ET!

Load more