Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Die XZ-Backdoor: Weckruf für die Open-Source-Sicherheit
2+ day, 22+ hour ago (249+ words) Um das Ausmaß des Vorfalls zu verstehen, müssen wir die Ereignisse Schritt für Schritt nachvollziehen. Es ist eine Geschichte, die sich wie ein Cyber-Thriller liest, aber bittere Realität ist. Hätte Freund diese kleine Anomalie ignoriert, wäre die Backdoor unentdeckt in…...
Shai-Hulud npm worm resurfaces, bypassing security scans
3+ day, 5+ hour ago (80+ words) As outlined in IT Pro, the Shai-Hulud npm worm, previously thought to be neutralized, has reappeared in a new campaign that successfully bypassed npm's recently implemented security measures. The targeted entities are developers and organizations relying on the npm registry…...
We Analyzed a Malicious PyPl Package Targeting Developers
3+ day, 18+ hour ago (196+ words) A developer runs pip install. Nothing crashes. No ransomware appears. No antivirus alert fires. Thirty seconds later, a Python process makes an outbound connection to infrastructure nobody on the team recognizes. Recent 2026 incidents show how quickly this can become a…...
npm Supply Chain Worm Returns After Four-Month Dormancy With Same Malicious Payload
4+ day, 22+ hour ago (330+ words) A previously documented Shai-Hulud npm supply-chain worm payload has reportedly reappeared after 111 days of inactivity, using the exact same malicious file linked to the May 19 compromise of hundreds of @AntV package versions. The reactivation raises concerns about registry-level malware detection…...
Shai-Hulud Malware Returns to npm Unchanged, 111 Days After Its Hash Was Fingerprinted
4+ day, 19+ hour ago (507+ words) Four packages is a small blast radius next to the 639 malicious versions pushed during the May campaign. The significance sits elsewhere. npm rolled out publish-time scanning in July, a control that briefly holds new publications for automated analysis before they…...
A Shai-Hulud npm payload came back 111 days later
5+ day, 15+ hour ago (396+ words) Advanced AppSec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Since then, npm has introduced publish-time malware scanning. So you can imagine my surprise when I was going through our triage queue this morning…...
JSCeal Hides Crypto Malware in V8 Bytecode
5+ day, 18+ hour ago (764+ words) Why AI Agent Sandboxes Are Failing Security Tests Berlin Ransomware Leak Exposes State Secrets Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure Security Affairs newsletter Round 593 by…...
Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic
6+ day, 18+ hour ago (517+ words) Rescana Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic Technical Analysis of Malware/TTPs The Ted backdoor is not a vulnerability in the official HAProxy codebase, but rather a malicious plugin…...
ChainDrop npm Worm: 444 Packages Infected in 4 Hours
1+ week, 9+ hour ago (731+ words) Once triggered, the background task restarts the credential-harvesting cycle on the newly infected machine, which is what gives ChainDrop its worm-like, self-sustaining spread across a team or an organization rather than a single compromised build. For command and control, ChainDrop…...
Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs
1+ week, 4+ day ago (564+ words) Iran-linked threat actor Mirage Kitten is targeting software developers with fake recruitment assessments that hide two newly identified cross-platform remote access trojans: NodeRabbit and PollCat. The campaign uses recruiter impersonation on LinkedIn and other job-search platforms, weaponized Node.js projects,…...