Microsoft attributes Mastra AI npm supply chain attack to North Korean hacking group Sapphire Sleet

A large npm supply chain compromise affecting over 140 Mastra AI packages has been linked to the North Korean threat group Sapphire Sleet, which deployed malware to steal credentials and cryptocurrency assets.

The Latest

Breaking News and Alerts

Researchers uncover DifyTap vulnerabilities in Dify that could expose cross-tenant AI chat data

Researchers disclosed “DifyTap,” a set of Dify vulnerabilities that could let attackers bypass tenant isolation and secretly access private AI chat data, files, and model outputs across different user environments.

Spotlight

Cybersecurity Profiles and Stories

MEV Bot ‘JaredFromSubway’ Targeted in $15 Million Crypto Heist

An attacker tricked an Ethereum MEV bot into approving malicious contracts by spoofing profitable trading opportunities, ultimately draining about $15 million in crypto assets through accumulated token allowances.

Fake Business Documents in WhatsApp Attack Lead to PC Infections

A global WhatsApp phishing campaign is using fake business documents and compromised accounts to trick users into installing remote-access malware on Windows PCs.

State Surveillance Expands Through AI and Biometric Tracking Across 31 High Risk Nations

A new analysis of 193 countries finds that government digital surveillance poses high risk in 31 nations, with commercial spyware and AI tools accelerating the threat globally.

Gentlemen RaaS Deploys Suite of EDR Evasion Tools to Sidestep Security Defenses

ESET researchers found that the Gentlemen ransomware gang uses a custom tool called GentleKiller with eight variants to disable over 400 security processes across 48 vendors.

Features

Research and Thought Leadership