Nearly 800 Malicious npm Packages: Cross-Platform Threat
Nearly 800 malicious npm packages have been published to npm, aiming to infect Windows, macOS, and Linux. The campaign uses an npm require-based loader to fetch and execute staged malware.
Nearly 800 malicious npm packages have been published to npm, aiming to infect Windows, macOS, and Linux. The campaign uses an npm require-based loader to fetch and execute staged malware.
ClickFix attacks macOS start with a pasted Terminal command and deliver a Go-based stealer. Besides passwords and iCloud Keychain, the malware can gradually drain crypto wallets.
The UNC6671 vishing campaign targets enterprise employees by calling their personal mobile numbers and guiding them to spoofed login pages. Stolen credentials and MFA tokens are then used to access and exfiltrate data from SaaS platforms.
From ChatGPT-driven scam networks to port outages and router backdoors, this cybersecurity roundup covers the week’s most notable security developments and why they matter.
WordPress has patched a high-severity pre-auth XSS in its login screen (CVE-2026-64638). Attackers could potentially escalate to PHP code execution via administrator interaction, so update now.
Open source isn’t disappearing—it’s being conscripted. Enterprise Open Source will split the ecosystem into projects that can prove ongoing viability and those that won’t fit regulated needs.
Een oude use-after-free in Linux’ SCTP-netwerkcode kan in specifieke situaties leiden tot root op de host. Onderzoekers melden bovendien pogingen om containers te ontsnappen, waarna een kernelupdate dringend is.
UNC6671 vishing extortion has rebranded across several names after earning millions. Attackers keep using IT helpdesk impersonation, AiTM, and phishing panels to harvest credentials.
PortSwigger’s AI-Assisted HTTP Terminator generated and proved new HTTP desynchronization techniques by testing thousands of authorized targets. The work also surfaced a patched Apache Traffic Server zero-day and a broader attack concept.
A safety recall for a heavy-truck brake controller included far more than a reliability update. New research links the change to serious security weaknesses that could be triggered remotely.