FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Hacker News

48 Malicious npm Packages Found Deploying Reverse Shells on Developer Systems

By: Newsroom β€” November 3rd 2023 at 06:03
A new set of 48 malicious npm packages have been discovered in the npm repository with capabilities to deploy a reverse shell on compromised systems. "These packages, deceptively named to appear legitimate, contained obfuscated JavaScript designed to initiate a reverse shell on package install," software supply chain security firm PhylumΒ said. All the counterfeit packages have been published by
☐ β˜† βœ‡ The Hacker News

Malicious NuGet Packages Caught Distributing SeroXen RAT Malware

By: Newsroom β€” October 31st 2023 at 12:04
Cybersecurity researchers have uncovered a new set of malicious packages published to the NuGet package manager using a lesser-known method for malware deployment. Software supply chain security firm ReversingLabs described the campaign as coordinated and ongoing since August 1, 2023, while linking it to aΒ host of rogue NuGet packagesΒ that were observed delivering a remote access trojan called
☐ β˜† βœ‡ The Hacker News

N. Korean Lazarus Group Targets Software Vendor Using Known Flaws

By: Newsroom β€” October 27th 2023 at 14:57
The North Korea-alignedΒ Lazarus GroupΒ has been attributed as behind a new campaign in which an unnamed software vendor was compromised through the exploitation of known security flaws in another high-profile software. The attack sequences, according to Kaspersky, culminated in the deployment of malware families such as SIGNBT andΒ LPEClient, a known hacking tool used by the threat actor for
☐ β˜† βœ‡ The Hacker News

GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contributions

By: THN β€” September 28th 2023 at 17:22
A new deceptive campaign has been observed hijacking GitHub accounts and committing malicious code disguised as Dependabot contributions with an aim to steal passwords from developers. "The malicious code exfiltrates the GitHub project's defined secrets to a malicious C2 server and modify any existing javascript files in the attacked project with a web-form password-stealer malware code
☐ β˜† βœ‡ The Hacker News

Ukrainian Hacker Suspected to be Behind "Free Download Manager" Malware Attack

By: THN β€” September 21st 2023 at 08:48
The maintainers of Free Download Manager (FDM) have acknowledged a security incident dating back to 2020 that led to its website being used to distribute malicious Linux software. "It appears that a specific web page on our site was compromised by a Ukrainian hacker group, exploiting it to distribute malicious software," itΒ saidΒ in an alert last week. "Only a small subset of users, specifically
☐ β˜† βœ‡ The Hacker News

Fresh Wave of Malicious npm Packages Threaten Kubernetes Configs and SSH Keys

By: THN β€” September 20th 2023 at 10:13
Cybersecurity researchers have discovered a fresh batch of malicious packages in the npm package registry that are designed to exfiltrate Kubernetes configurations and SSH keys from compromised machines to a remote server. Sonatype said it has discovered 14 different npm packages so far: @am-fe/hooks, @am-fe/provider, @am-fe/request, @am-fe/utils, @am-fe/watermark, @am-fe/watermark-core, @
☐ β˜† βœ‡ The Hacker News

Developers Beware: Malicious Rust Libraries Caught Transmitting OS Info to Telegram Channel

By: THN β€” August 28th 2023 at 15:40
In yet another sign that developers continue to be targets of software supply chain attacks, a number of malicious packages have been discovered on the Rust programming language's crate registry. The libraries, uploaded between August 14 and 16, 2023, were published by a user named "amaperf," PhylumΒ saidΒ in a report published last week. The names of the packages, now taken down, are as follows:
☐ β˜† βœ‡ The Hacker News

Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates

By: THN β€” August 22nd 2023 at 10:12
A previously undocumented threat cluster has been linked to a software supply chain attack targeting organizations primarily located in Hong Kong and other regions in Asia. The Symantec Threat Hunter Team, part of Broadcom, is tracking the activity under its insect-themed moniker Carderbee. The attacks, per the cybersecurity firm, leverage a trojanized version of a legitimate software called
☐ β˜† βœ‡ The Hacker News

Experts Uncover Weaknesses in PowerShell Gallery Enabling Supply Chain Attacks

By: THN β€” August 16th 2023 at 11:56
Active flaws in the PowerShell Gallery could be weaponized by threat actors to pull off supply chain attacks against the registry's users. "These flaws make typosquatting attacks inevitable in this registry, while also making it extremely difficult for users to identify the true owner of a package," Aqua security researchers Mor Weinberger, Yakir Kadkoda, and Ilay Goldman said in a report shared
☐ β˜† βœ‡ The Hacker News

North Korean State-Sponsored Hackers Suspected in JumpCloud Supply Chain Attack

By: THN β€” July 20th 2023 at 13:30
An analysis of the indicators of compromise (IoCs) associated with the JumpCloud hack has uncovered evidence pointing to the involvement of North Korean state-sponsored groups, in a style that's reminiscent of theΒ supply chain attack targeting 3CX. The findings come from SentinelOne, whichΒ mapped outΒ the infrastructure pertaining to the intrusion to uncover underlying patterns. It's worth noting
☐ β˜† βœ‡ Naked Security

S3 Ep136: Navigating a manic malware maelstrom

By: Paul Ducklin β€” May 25th 2023 at 16:50
Latest episode - listen now. Full transcript inside...

☐ β˜† βœ‡ Naked Security

PyPI open-source code repository deals with manic malware maelstrom

By: Paul Ducklin β€” May 23rd 2023 at 16:45
Controlled outage used to keep malware marauders from gumming up the works. Learn what you can do to help in future...

☐ β˜† βœ‡ Naked Security

PHP Packagist supply chain poisoned by hacker β€œlooking for a job”

By: Paul Ducklin β€” May 5th 2023 at 16:59
I pwned you! Gizza job! You know it makes sense!

☐ β˜† βœ‡ Naked Security

Attention gamers! Motherboard maker MSI admits to breach, issues β€œrogue firmware” alert

By: Paul Ducklin β€” April 11th 2023 at 16:58
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

☐ β˜† βœ‡ Naked Security

S3 Ep129: When spyware arrives from someone you trust

By: Paul Ducklin β€” April 6th 2023 at 14:57
Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!

☐ β˜† βœ‡ Naked Security

S3 Ep113: Pwning the Windows kernel – the crooks who hoodwinked Microsoft [Audio + Text]

By: Paul Ducklin β€” December 15th 2022 at 17:10
Return o' the rookit, super-sneaky wireless spyware, credit card skimming, and patches galore. Listen and learn!

☐ β˜† βœ‡ Naked Security

TikTok β€œInvisible Challenge” porn malware puts us all at risk

By: Paul Ducklin β€” November 29th 2022 at 17:58
An injury to one is an injury to all. Especially if the other people are part of your social network.

☐ β˜† βœ‡ Naked Security

GitHub blighted by β€œresearcher” who created thousands of malicious projects

By: Paul Ducklin β€” August 3rd 2022 at 23:06
If you spew projects laced with hidden malware into an open source repository, don't waste your time telling us "no harm done" afterwards.

☐ β˜† βœ‡ Naked Security

Poisoned Python and PHP packages purloin passwords for AWS access

By: Paul Ducklin β€” May 24th 2022 at 23:04
More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

☐ β˜† βœ‡ Naked Security

GitHub issues final report on supply-chain source code intrusions

By: Paul Ducklin β€” April 29th 2022 at 16:15
Learn how to find out which apps you've given access rights to, and how to revoke those rights immediately in an emergency.

☐ β˜† βœ‡ Naked Security

JavaScript developer destroys own projects in supply chain β€œlesson”

By: Paul Ducklin β€” January 11th 2022 at 00:54
Two popular open source JavaScript packages recently got "hacked" in a symbolic gesture by the original project creator.

❌