Visualização normal

Antes de ontemStream principal

Major Supply Chain Compromise in the Popular axios npm Package

3 de Abril de 2026, 09:28

On March 30, 2026, two malicious versions of the widely used axios HTTP client library were published to npm; axios@1.14.1 and axios@0.30.4. The malicious versions inject a new dependency, plain-crypto-js@4.2.1, which, in turn, downloads a Remote Access Toolkit (RAT).

  • ✇SpiderLabs Blog
  • Sha1-Hulud: The Second Coming of The New npm GitHub Worm Karl Sigler
    Sha1-Hulud is back with a new evolution of its supply-chain attack that targets development environments via Node Package Manager (npm). npm is a very popular package manager for Node.js that provides millions of predeveloped packages of code to be used by JavaScript developers for access to millions of packages.  
     

Sha1-Hulud: The Second Coming of The New npm GitHub Worm

3 de Dezembro de 2025, 11:00

Sha1-Hulud is back with a new evolution of its supply-chain attack that targets development environments via Node Package Manager (npm). npm is a very popular package manager for Node.js that provides millions of predeveloped packages of code to be used by JavaScript developers for access to millions of packages.  

US Secret Service Blocks Massive Telecom Attack in New York

24 de Setembro de 2025, 10:00

The Secret Service’s takedown in New York shines a light on a type of threat that is technically fascinating and deeply concerning for national security: large-scale cellular interception networks leveraging cell-site simulators (CSS), also known as IMSI catchers or Stingrays.

Salesloft Drift Supply Chain Attack Affects Hundreds of Businesses

9 de Setembro de 2025, 17:44

Trustwave's Security & Compliance Team is aware of the Salesloft vulnerability affecting Drift chatbot integrations. Trustwave, A LevelBlue Company, and its affiliated entities do not utilize Drift, and Salesforce has confirmed the incident did not impact clients without this integration.

  • ✇SpiderLabs Blog
  • Sha1-Hulud: The Second Coming of The New npm GitHub Worm Karl Sigler
    Sha1-Hulud is back with a new evolution of its supply-chain attack that targets development environments via Node Package Manager (npm). npm is a very popular package manager for Node.js that provides millions of predeveloped packages of code to be used by JavaScript developers for access to millions of packages.  
     

Sha1-Hulud: The Second Coming of The New npm GitHub Worm

3 de Dezembro de 2025, 11:00

Sha1-Hulud is back with a new evolution of its supply-chain attack that targets development environments via Node Package Manager (npm). npm is a very popular package manager for Node.js that provides millions of predeveloped packages of code to be used by JavaScript developers for access to millions of packages.  

  • ✇SpiderLabs Blog
  • The F5 BIG-IP Source Code Breach Karl Sigler
    On August 9, F5 discovered that multiple systems were compromised by what it is calling a "highly sophisticated nation-state threat actor" who maintained "long-term, persistent access to certain F5 systems". These included the BIG-IP product development environment and engineering knowledge management platform. That access allowed for the exfiltration of portions of F5's BIG-IP source code as well as information about undisclosed BIG-IP vulnerabilities F5 was working on.
     

The F5 BIG-IP Source Code Breach

17 de Outubro de 2025, 13:29

On August 9, F5 discovered that multiple systems were compromised by what it is calling a "highly sophisticated nation-state threat actor" who maintained "long-term, persistent access to certain F5 systems". These included the BIG-IP product development environment and engineering knowledge management platform. That access allowed for the exfiltration of portions of F5's BIG-IP source code as well as information about undisclosed BIG-IP vulnerabilities F5 was working on.

❌
❌