Visualização normal

Antes de ontemWIZ Cloud Threat Landscape

Payroll Pirates Phishing Campaign Targets Microsoft 365 Financial Workflows (Campaign)

The attack begins with phishing emails impersonating voicemail notifications that direct victims through a multi-stage redirect chain abusing legitimate services, including Google Meet, Google Ads infrastructure, and Amazon S3, before ultimately reaching an attacker-controlled...

keyv and cacheable npm Package Hijacked in Supply Chain Attack (Campaign)

Multiple npm packages in the keyv/cacheable ecosystem were compromised following the compromise of a GitHub maintainer account, resulting in the publication of malicious package versions. All versions shared a consistent payload. Starting at 9:00 UTC, the attacker first used a...

CaptiveCrunch: Midnight Blizzard Hospitality Network AiTM Campaign (Campaign)

Microsoft Threat Intelligence identified CaptiveCrunch, an ongoing cyberespionage campaign conducted by Storm-2945, a subgroup of the Russian state-sponsored actor Midnight Blizzard. The campaign compromises hospitality-sector captive portal infrastructure to perform adversary...

Cl0p Exploitation of PTC Windchill and FlexPLM Vulnerability (Campaign)

The observed attack chain begins with reconnaissance against the FlexPLM WSDL endpoint, followed by exploitation of the information disclosure vulnerability and CVE-2026-12569, a deserialization flaw that enables unauthenticated remote code execution. Attackers deploy hex-name...

SleeperGem: RubyGems Supply Chain Attack Targets Dormant Maintainer Accounts (Campaign)

On July 18-19, 2026, an attacker compromised at least two dormant RubyGems maintainer accounts (inactive since 2019) to publish malicious gem versions. The attack was discovered when git_credential_manager appeared with suspicious behavior—downloading binaries from a public Fo...

NadMesh: Autonomous AI-Focused Botnet Targeting Cloud and AI Infrastructure (Campaign)

NadMesh uses a centralized controller to coordinate scanning across large IP ranges and attempts exploitation using more than 20 supported attack vectors. The malware targets exposed services such as Docker APIs, Kubernetes APIs, Redis, Elasticsearch, Jenkins, WebLogic, and MC...

CVE-2025-54068 Exploited in Large-Scale Laravel Livewire Credential Theft Campaign (Campaign)

A large-scale credential theft campaign exploiting CVE-2025-54068, a critical unauthenticated remote code execution vulnerability in Laravel Livewire v3. Attackers used PHP deserialization to execute a Bash-based credential stealer that harvested sensitive application secrets ...

AsyncAPI Supply Chain Compromise via GitHub Actions (Campaign)

On July 14, 2026, an attacker opened 37 pull requests to the AsyncAPI generator repository. Almost all attempted to add a fake charity donation page. Camouflage in the noise, a single PR exploited a misconfigured GitHub Actions workflow to steal a highly privileged Personal Ac...

Cryptomining campaign targeting Linux SSH servers (Campaign)

AhnLab ASEC identified an ongoing Linux-targeted cryptomining campaign that compromises internet-exposed SSH servers using brute-force attacks against weak credentials. Once access is obtained, attackers deploy a multi-stage malware toolkit consisting of Go-based downloaders a...

Jscrambler npm Package Compromised in Supply Chain Attack (Campaign)

A malicious version of the Jscrambler npm package, jscrambler@8.14.0, was published at 15:12 UTC on 11 July 2026. The compromised release executed a dropper via an npm preinstall hook that detected the host operating system and extracted a platform-specific native binary for W...

Compromised Injective SDK npm Package Exfiltrates Cryptocurrency Wallet Keys (Campaign)

A malicious version of the @injectivelabs/sdk-ts npm package (version 1.20.21) was briefly published to the official Injective Labs npm namespace after a contributor account was compromised. The package contained credential-stealing functionality that silently exfiltrated cryp...

Coordinated GitHub API Enumeration and Access Token Abuse (Campaign)

Datadog Security Labs identified multiple coordinated campaigns abusing the GitHub API to systematically enumerate organizations, repositories, users, and software development activity at scale. The activity primarily relied on legitimate GitHub functionality, including dorman...

Klue Supply Chain Breach Leads to Salesforce Data Exfiltration (Incident)

According to investigations, the compromise began when attackers gained access to Klue backend systems and deployed code capable of harvesting OAuth tokens used by customers to integrate Klue with third-party platforms such as Salesforce, Gong, SharePoint, HubSpot, Slack, and ...

Mastra Packages Trojanized with Malicious Dependency (Campaign)

On 17 June 2026, attackers compromised a maintainer account associated with the Mastra npm organization and used it to republish 116 packages over a 27-minute period. Rather than modifying Mastra’s source code directly, the threat actor injected a malicious dependency, easy-da...

FortiBleed: Credential Compromise Campaign Targeting Fortinet Devices (Campaign)

According to the research, the threat actor operates an automated infrastructure that scans the internet for Fortinet devices and attempts authentication using a curated set of previously leaked or compromised credentials. Successful logins are recorded and continuously revali...

Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Package (Campaign)

Researchers have disclosed a software supply chain attack, dubbed "Atomic Arch," targeting orphaned packages in the Arch User Repository (AUR). Using newly created AUR accounts, an attacker adopted more than 400 abandoned packages through the legitimate maintainer-handoff mech...

TeamPCP adds Malware to Multiple Microsoft-Linked GitHub Projects (Campaign)

TeamPCP has leveraged a compromised GitHub account to inject malicious code into at least 42 repositories and 236 branches across the Azure, Azure-Samples and Microsoft GitHub organizations. They were published between 02:36 and 03:22 UTC on 5 June 2026. As of 14:00 UTC on 5 J...

Binding.gyp Supply Chain Attack Enables CI/CD Worm Propagation Across npm Packages (Campaign)

Researchers identified an active supply chain attack affecting multiple npm packages that leverages a novel abuse of the binding.gyp build mechanism to execute malicious code during package installation. Unlike traditional npm supply chain attacks that rely on preinstall or po...

❌
❌