Android Zero-Click Shell, Apache RCE, Ivanti 0-Day, and Chrome 148 Patch Roundup

A wave of critical vulnerabilities and active attack campaigns demands immediate patching across Android, Apache, Chrome, Linux, and enterprise platforms.

The Latest

Breaking News and Alerts

Fake TanStack npm Package Steals Developer Credentials via Postinstall Script

Security researchers uncovered a supply chain attack where a fake TanStack npm package used automated postinstall scripts to harvest environment files containing API keys, tokens, and credentials.

Spotlight

Cybersecurity Profiles and Stories

New Supply Chain Worm Hits SAP npm Packages, Targets Developer Secrets

The Mini Shai-Hulud worm uses a Bun runtime bootstrap to silently harvest credentials from developer machines, cloud platforms, and AI coding tools before npm install completes.

Apache MINA Flaws Expose Enterprise Apps to Full Takeover

A botched merge left critical Apache MINA deserialization fixes unpublished until project maintainers caught the error and reissued versions 2.2.7 and 2.1.12.

FBI and Dubai Police Dismantle Global Crypto Fraud Ring, Seizing $701 Million

The international operation involved 276 arrests and the shutdown of nine scam centers, with human trafficking victims forced to run pig butchering schemes targeting Americans.

AI Driven Zero Day Discovery Now Automates Attacks at Machine Speed

Attackers now use AI models to discover and exploit zero day vulnerabilities in minutes, with documented campaigns like GAMECHANGE showing LLMs orchestrating espionage in real time.

Features

Research and Thought Leadership