Researchers have uncovered Operation BlueDash, a phishing campaign that uses fake Microsoft Teams updates to deploy remote access tools and establish persistent access to Windows systems.
Viper Technology CEO Khushnood Aftab Shaikh met Sindh IT Company CEO Zainulabedin Shah to discuss potential collaboration opportunities focused on innovation and business growth.
Threat actors compromised popular GitHub Actions workflows to exfiltrate CI/CD credentials through malicious code, raising concerns around software supply chain security and GitHub repository integrity.
A Mini Shai Hulud worm linked to TeamPCP has compromised npm and PyPI packages across TanStack, Mistral AI, Guardrails AI and others, deploying credential stealers, CI/CD exploits, and cross ecosystem propagation techniques.
Security researchers report malicious Docker images and VS Code extensions tied to Checkmarx supply chain compromise, exposing developer credentials, cloud tokens, and CI/CD secrets through multi-stage malware and npm propagation.
OpenAI revokes its macOS app signing certificate after a malicious Axios supply chain attack, confirming no user data compromise while outlining security measures and broader ecosystem risks.
A compromised npm publish token was used to release Cline CLI version 2.3.0, triggering unauthorized installation of OpenClaw on developer systems during an eight hour supply chain attack window.