Topic: security response
-
Urgent Unity Security Update Required for All Games
A critical security vulnerability in Unity requires developers using versions 2017.1 or later for Windows, Android, or macOS to update immediately to prevent potential risks like malicious code execution. Unity's partners, including Valve and Microsoft, have implemented security measures, and the...
Read More » -
Salesforce Refuses to Pay Ransom in Massive Data Breach
Salesforce has refused to pay a ransom after a data breach allegedly exposed nearly one billion customer records, emphasizing its policy against negotiating with cybercriminals despite the risk of data exposure. The attack, initiated in May, involved English-speaking operatives tricking employees...
Read More » -
ChainDrop npm Attack Infects Hundreds of Packages
ChainDrop, a self-replicating worm based on the Shai-Hulud framework, compromised over 1,300 npm packages (including Keyv, Cacheable, and flat-cache) by seizing a maintainer's GitHub account and pushing malicious releases through legitimate CI workflows with valid provenance. Each infected packag...
Read More » -
LiteLLM Malware Attack: Delve Security Compliance Review
A major security breach occurred in the popular open-source AI tool LiteLLM, where malware was discovered stealing credentials via a compromised software dependency, raising concerns about software supply chain security. The incident has sparked scrutiny of LiteLLM's advertised security certifica...
Read More » -
Trust Wallet Ties $8.5M Crypto Theft to NPM Attack
A major security breach at Trust Wallet, linked to the "Sha1-Hulud" supply chain attack, resulted in the theft of approximately $8.5 million from over 2,500 wallets in late December. The attackers compromised the official Chrome extension by inserting malicious code, enabled by exposed developer ...
Read More » -
Urgent: Actively Exploited WSUS Bug Now on CISA KEV List
A critical security flaw (CVE-2025-59287) in Windows Server Update Services (WSUS) allows unauthenticated attackers to execute remote code with system privileges by exploiting the GetCookie() endpoint. The vulnerability is under active exploitation, prompting urgent patching by Microsoft and incl...
Read More » -
Flickr warns of data breach exposing user emails and names
A security flaw in an external email provider for a major photo-sharing platform potentially exposed user data like names, email addresses, and IP addresses, though financial data and passwords were not compromised. The company acted quickly to contain the breach, terminated access to the affecte...
Read More » -
Partiful Exposed User Locations in Uploaded Photos
Partiful has become a leading social event planning app, surpassing Facebook in popularity due to its retro designs and easy RSVP system, earning it Google's best app of 2024 award. The app faced scrutiny over data privacy, as it failed to strip location metadata from user-uploaded photos, potent...
Read More » -
Trivy Scanner Compromised in Major Supply-Chain Attack
A supply-chain attack compromised nearly all versions of the Trivy vulnerability scanner after attackers used stolen credentials to force malicious code into its Git repository. The injected malware harvests sensitive data like GitHub tokens and cloud credentials from development pipelines and ma...
Read More » -
Inside the Market for Stolen Login Credentials
Cybercriminals have evolved from selling bulk credential dumps to offering targeted "search-your-target" services, where buyers can request credentials for specific companies, platforms, or regions from massive infostealer databases. Analysis of 470 underground forum posts reveals a dedicated ser...
Read More » -
Hackers Hijack CPUID Downloads to Distribute STX RAT
The official website of CPUID, a provider of popular system utilities like HWMonitor and CPU-Z, was compromised between April 9-10, 2026, redirecting users to malicious downloads in a watering hole attack. Attackers distributed trojanized software using a DLL sideloading technique, which deployed...
Read More » -
Fake npm 2FA Reset Email Used to Hijack Popular Code Packages
A phishing campaign compromised at least 18 widely used JavaScript npm packages, injecting malicious code to hijack cryptocurrency transactions and highlighting supply chain vulnerabilities. The attack began when a developer fell for a convincing phishing email, allowing the threat actor to take ...
Read More » -
LiteLLM PyPI packages hijacked in TeamPCP supply chain attacks
A coordinated software supply chain attack by the group TeamPCP compromised the popular LiteLLM library on March 24, uploading malicious versions to PyPI that contained credential stealers and malware droppers. The attack targeted a critical point in the AI application stack, risking exposure of ...
Read More » -
Critical Server Vulnerability Sparks Urgent Admin Response
A critical, maximum-severity vulnerability in the widely used React Server package allows attackers to easily execute arbitrary code via a single HTTP request, with public exploit code now available. The flaw's danger is amplified because React is integrated by default into many popular framework...
Read More » -
Rust Developers Targeted in New Phishing Campaign
A new phishing campaign is targeting Rust developers via emails that mimic official security breach notifications from the Rust Foundation, attempting to steal GitHub credentials. The fraudulent messages directed users to a fake login portal, but officials confirmed no actual breach occurred and ...
Read More » -
American Archive of Public Broadcasting Patches Security Flaw
A security flaw in the American Archive of Public Broadcasting (AAPB) website allowed unauthorized downloads of protected media files for years, which was exploited since at least 2021 and has now been fixed. The vulnerability was an Insecure Direct Object Reference (IDOR) flaw that let users byp...
Read More » -
Insight Partners Confirms Ransomware Data Breach
Insight Partners suffered a ransomware attack that compromised sensitive personal and financial information, affecting over 12,000 individuals. The breach began in October 2024, went undetected for months, and involved advanced social engineering tactics for initial network access. Despite invest...
Read More » -
Microsoft Entra ID Flaw: The Critical Security Risk You Can't Ignore
Security researcher Dirk-jan Mollema discovered two critical vulnerabilities in Microsoft Entra ID that could allow attackers to gain global administrator privileges across nearly all customer tenants. The flaws, involving legacy components like the Access Control Service and Azure Active Directo...
Read More » -
Nissan Data Breach: Thousands Affected by Red Hat Hack
A data breach at software firm Red Hat compromised a server, exposing the personal information of approximately 21,000 Nissan customers in Japan, though no financial data was stolen. Nissan states there is no evidence of fraudulent misuse of the data, but the breach is part of a larger cyberattac...
Read More »