Detecting vulnerable code in software dependencies is more complex than it seemsHelp Net Security·Sep 18, 00:00 UTC · Sep 18, 2024Vulnerability30
EchoStrike: Generate undetectable reverse shells, perform process injectionHelp Net Security·Sep 16, 00:00 UTC · Sep 16, 2024AI safety & security30
Trends and dangers in open-source software dependenciesHelp Net Security·Sep 16, 00:00 UTC · Sep 16, 2024Vulnerability155
VirtualBox 7.1: This is a major update, here's what's newHelp Net Security·Sep 12, 00:00 UTC · Sep 12, 2024AI research30
New PyPI Malware “Pytoileur” Steals Crypto and Evades DetectionInfosecurity Magazine·May 29, 16:15 UTC · May 29, 2024Malware30
“Highly capable” hackers root corporate networks by exploiting firewall 0Ars Technica · Security·Apr 12, 20:48 UTC · Apr 12, 2024Exploit / PoC in the wildCVE-2024-340060
PyPI halted new users and projects while it fended off supplyArs Technica · Security·Mar 28, 18:50 UTC · Mar 28, 2024Malware42
Transitioning to memory-safe languages: Challenges and considerationsHelp Net Security·Mar 11, 00:00 UTC · Mar 11, 2024Vulnerability155
Lazarus Exploits Typos to Sneak PyPI Malware into Dev SystemsThe Hacker News·Feb 29, 10:58 UTC · Feb 29, 2024Malware30
North Korean Hackers Targeting Developers with Malicious npm PackagesThe Hacker News·Feb 27, 04:27 UTC · Feb 27, 2024Malware42
Warning: New Malware Emerges in Attacks Exploiting Ivanti VPN VulnerabilitiesThe Hacker News·Feb 2, 04:53 UTC · Feb 2, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Italian Businesses Hit by Weaponized USBs Spreading Cryptojacking MalwareThe Hacker News·Jan 31, 12:04 UTC · Jan 31, 2024Malware42
Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows MachinesThe Hacker News·Jan 29, 13:19 UTC · Jan 29, 2024Malware30
A deep dive into Phobos ransomware, recently deployed by 8Base groupCisco Talos·Nov 17, 13:01 UTC · Nov 17, 2023Ransomware57
Highly invasive backdoor snuck into open source packages targets developersArs Technica · Security·Nov 8, 18:27 UTC · Nov 8, 2023Malware42
North Korean Hackers Targeting Crypto Experts with KANDYKORN macOS MalwareThe Hacker News·Nov 1, 14:38 UTC · Nov 1, 2023Malware42
NodeStealer Malware Now Targets Facebook Business Accounts on Multiple BrowsersThe Hacker News·Sep 18, 03:04 UTC · Sep 18, 2023Malware30
Hackers are spreading malware via trending TikTok challenge: reportThe Record·Jan 9, 00:00 UTC · Jan 9, 2023Malware55
Malicious PyPI package posed as SentinelOne SDK to serve infoSecurity Affairs·Dec 20, 00:59 UTC · Dec 20, 2022Malware42
Experts detailed a previously undetected VMware ESXi backdoorSecurity Affairs·Dec 13, 14:15 UTC · Dec 13, 2022MalwareCVE-2019-5544CVE-2020-399247
Hackers Using Trending TikTok 'Invisible Challenge' to Spread MalwareThe Hacker News·Nov 29, 13:18 UTC · Nov 29, 2022Malware42
Experts warn of malicious packages on PyPI using steganographySecurity Affairs·Nov 10, 16:15 UTC · Nov 10, 2022Malware30
Researchers Uncover 29 Malicious PyPI Packages Targeted Developers with W4SP StealerThe Hacker News·Nov 5, 08:35 UTC · Nov 5, 2022Malware42
Experts warn of the first known phishing attack against PyPISecurity Affairs·Aug 28, 15:36 UTC · Aug 28, 2022Phishing & fraud55
Serpent backdoor targets French entities with highSecurity Affairs·Mar 22, 05:36 UTC · Mar 22, 2022Malware42
FreakOut botnet target 3 recent flaws to compromise Linux devicesSecurity Affairs·Oct 12, 22:18 UTC · Oct 12, 2021MalwareCVE-2020-28188CVE-2021-3007CVE-2020-796147
Researchers discover ransomware that encrypts virtual machines hosted on an ESXi hypervisorHelp Net Security·Oct 7, 00:00 UTC · Oct 7, 2021Ransomware60
Experts found potential remote code execution in PyPISecurity Affairs·Aug 3, 08:27 UTC · Aug 3, 2021Vulnerability42
Six typosquatting packages in PyPI repository laced with crypto minerSecurity Affairs·Jun 28, 06:46 UTC · Jun 28, 2021Vulnerability55
Microsoft is open sourcing CyberBattleSim SimulatorSecurity Affairs·Apr 12, 16:21 UTC · Apr 12, 2021Ransomware157
What did DeathStalker hide between two ferns?Kaspersky Securelist·Dec 3, 10:00 UTC · Dec 3, 2020Malware42
Adobe released open- source tool Stringlifier to identify randomly generated stringsSecurity Affairs·Aug 23, 06:56 UTC · Aug 23, 2020Tools30
Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript ZeroPalo Alto Unit 42·Jul 3, 01:11 UTC · Jul 3, 2020Exploit / PoCCVE-2016-6957CVE-2016-695860
Pakistan and India to armaments:Operation Transparent Tribe 4 years laterSecurity Affairs·Feb 21, 14:07 UTC · Feb 21, 2020Vulnerability30
JhoneRAT uses Google Drive, Twitter, ImgBB, and Google Forms to target countries in Middle EastSecurity Affairs·Jan 20, 08:10 UTC · Jan 20, 2020Malware30
Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor's RepositoryPalo Alto Unit 42·Nov 5, 09:23 UTC · Nov 5, 2018Threat actorCVE-2012-015850
Recent InPage Exploits Lead to Multiple Malware FamiliesPalo Alto Unit 42·Nov 1, 10:56 UTC · Nov 1, 2018Malware42
Magic Hound Campaign Attacks Saudi TargetsPalo Alto Unit 42·Nov 1, 10:44 UTC · Nov 1, 2018Threat actor45