Ad image

Malicious npm Packages Target Red Hat Developers with Credential Harvesting Worm

The Miasma campaign uses obfuscated install hooks in legitimate npm packages to steal credentials and secrets from developer machines while actively avoiding Russian language systems.

The Latest

Breaking News and Alerts

Iran-Linked Cyberattackers Wipe IT and Backups at US Transit Agencies and GPS Firm

Iran-linked hackers destroyed IT, backup, and recovery systems at LA Metro, South Florida transit, and a GPS tracking firm in a campaign that prevented data restoration.

Spotlight

Cybersecurity Profiles and Stories

WordPress Plugin Flaw Lets Attackers Take Over Sites via Admin Creation

Attackers are exploiting a privilege escalation bug in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on vulnerable websites.

Microsoft 365 MFA Setup Disruption Blocks User Enrollment and Portal Access

A Microsoft 365 outage is preventing users from setting up multi-factor authentication or accessing the MySigns-In portal, with no root cause or resolution timeline provided yet.

GitLab Fixes Critical Duo AI Identity and DoS Flaws in Latest Security Patches

The emergency patches address a high severity identity spoofing flaw in AI workflow runners and a denial of service bug in the Wiki component for self managed instances.

Healthcare Data Breach and Chrome Zero Day Highlight Critical Patching Needs

A healthcare data leak exposing biometrics and financial details and a separate Chrome zero day exploit underscore the growing urgency of prompt patching across all sectors.

Features

Research and Thought Leadership