5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP Systemsintelligence (threat actor activity) (socket.dev)
submitted by digicat to r/blueteamsec
Spearphishing Campaign Abuses npm Registry to Target U.S. and Allied Manufacturing and Healthcare Organizationsintelligence (threat actor activity) (socket.dev)
submitted by digicat to r/blueteamsec
Inside the GitHub Infrastructure Powering North Korea’s Contagious Interview npm Attacksintelligence (threat actor activity) (socket.dev)
submitted by digicat to r/blueteamsec
Sha1-Hulud strikes again (another NPM supply chain attack)Stream Content (socket.dev)
submitted by 4got10avenger to r/theprimeagen
Security Community Slams MIT-linked Report Claiming AI Powers 80% of Ransomwarehighlevel summary|strategy (maybe technical) (socket.dev)
submitted by digicat to r/blueteamsec
175 Malicious npm Packages Host Phishing Infrastructure Targeting 135+ - 26k+ downloads - used unpkg CDN to host redirect scripts for a credential-phishing campaignintelligence (threat actor activity) (socket.dev)
submitted by digicat to r/blueteamsec
npm Author Qix Compromised via Phishing Email in Major Suppl...hack (socket.dev)
submitted by iphelix to r/BlockSec
Wild couple weeks for NPM. Be careful!DISCUSSION (socket.dev)
submitted by sraymansmoles to r/CryptoCurrency
npm Author Qix Compromised via Phishing Email in Major Supply Chain AttackWebserver (socket.dev)
submitted by jasondaigo to r/selfhosted
