Ad image

New npm Malware Campaign Spreads Self-Replicating Rust-Based Stealer

Over 50 trojanized npm packages deliver a Rust-based stealer named IronWorm that uses stolen credentials to self-replicate across the supply chain.

The Latest

Breaking News and Alerts

Custom Web Shell Framework Found Targeting Microsoft IIS Servers

A new China linked threat group called OP-512 is using three custom web shells with timestamp manipulation to compromise Microsoft IIS servers for espionage purposes.

Spotlight

Cybersecurity Profiles and Stories

Microsoft Releases Urgent Patches for SharePoint Remote Code Execution Bug

A newly patched SharePoint vulnerability lets authenticated users with basic permissions execute code remotely on servers, prompting Microsoft to push fixes across multiple product versions.

Let’s Encrypt Bets on Compact Merkle Tree Proofs for Quantum Safe Web

The new MTC design replaces bulky serialized certificate chains with compact tree proofs to avoid performance degradation in TLS handshakes.

Laravel Framework Flaw Allows Outbound Email Manipulation

A CRLF injection flaw in Laravel lets attackers alter outbound emails by injecting control characters into user supplied addresses, with patches now available.

Flaw in AI Library Allows Code to Be Hidden in Model Files

A new exploit in the widely used Transformers library lets attackers execute code by uploading malicious model files that appear legitimate.

Features

Research and Thought Leadership