Velvet Ant APT Spent Years Hiding Inside Linux Login Stack

A China linked threat group compromised Linux PAM and OpenSSH components to maintain undetected access for nearly a decade, evading conventional security defenses.

The Latest

Breaking News and Alerts

npm 12 to Block Install Scripts by Default to Thwart Code Execution Attacks

npm version 12 will require explicit user approval for install scripts and Git dependencies to block automatic code execution from compromised packages.

Spotlight

Cybersecurity Profiles and Stories

OpenAI Introduces Lockdown Mode to Block Data Exfiltration via Prompt Injection

OpenAI launches Lockdown Mode for ChatGPT to limit outbound network requests and block data exfiltration pathways from prompt injection attacks.

Active Exploitation of Langflow File Write Bug Enables Remote Code Execution

Attackers are exploiting an unpatched path traversal vulnerability in the Langflow AI development platform that allows unauthenticated remote code execution through file writes.

One Click Attack on GitHub.dev Could Expose Private Repositories via VS Code

Researchers demonstrate how a single click can steal full access GitHub OAuth tokens through a vulnerability in the VS Code and GitHub.dev integration.

Features

Research and Thought Leadership