Security researchers have warned of a major new Shai-Hulud-based campaign which has already compromised more than 430 packages with a combined two billion monthly installs. The ChainDrop campaign began on August 4 when attackers compromised the GitHub account of a… Read More "ChainDrop Worm Hits 400 npm Packages with Two Billion Monthly Installs"
Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
https://assets.infosecurity-magazine.com/webpage/og/83928c6f-5f2e-451b-a4a1-f08723bdd838.jpeg Prompt injection attacks continue to present the most dangerous threat from large language models (LLMs), despite the relatively low number of recorded incidents relating to this vector, according to an updated analysis from the Open Worldwide Application Security Project… Read More "Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents"
Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
https://assets.infosecurity-magazine.com/webpage/og/3a46f5aa-1453-434f-b634-034b264fef3e.jpg Three vulnerabilities in an open-source AI agent orchestration platform have exposed sensitive data and allowed unauthenticated command execution on servers and developers’ machines, with two rated critical and one carrying a maximum CVSS score of 10.0. According to new… Read More "Paperclip AI Flaws Let Unauthenticated Attackers Run Commands"
Fake Open VSX Extensions Harvest Private Repo and CI Data
https://assets.infosecurity-magazine.com/webpage/og/f4a29ad1-4fd0-486b-951c-331808c46a96.jpg Counterfeit extensions impersonating real developer tools have been found on the Open VSX registry, with roughly a quarter of them harvesting the git and continuous integration identity of the organizations running them. New research Manifold Security published on August… Read More "Fake Open VSX Extensions Harvest Private Repo and CI Data"
Cybersecurity Job Ads Requiring AI Skills Double
https://assets.infosecurity-magazine.com/webpage/og/f2ac2454-1bdb-487a-8698-468b63688fa4.jpeg The number of cybersecurity job adverts that require AI skills have doubled year-over-year across G7 countries, encompassing over a quarter of new roles, according to new research by the Cisco-founded AI Workforce Consortium. Analysis of data from recruitment firms… Read More "Cybersecurity Job Ads Requiring AI Skills Double"
New Agent Tesla Malware Variant Boosts Evasion Capabilities
https://assets.infosecurity-magazine.com/webpage/og/d1c4c137-5571-4858-8a36-dbf5b4e0a746.jpeg A new version of the notorious Agent Tesla malware contains new features designed to evade detection and steal credentials, KnowBe4 research has identified. The cybersecurity firm provided a detailed analysis of the Agent Tesla version 4 infostealer, which was… Read More "New Agent Tesla Malware Variant Boosts Evasion Capabilities"
North Korean Hackers Tied to Rust Supply Chain Attack
https://assets.infosecurity-magazine.com/webpage/og/77fe36c5-e531-4591-afef-acbdc8585038.jpg Wiz security researchers have linked a recent software supply chain attack which targeted the Rust programming ecosystem to state-sponsored North Korean threat actors. The campaign compromised several widely used open-source libraries hosted on the official Rust package registry, crates.io,… Read More "North Korean Hackers Tied to Rust Supply Chain Attack"
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpRcdfXd6kYnqLLWSFdzGKICUzSr90MsV2f3PXtw8VDVcT-xOP2w4HwnVzrRI4bdJqhboQMFIm9BZ393b89IOqgYx-VVmb_B8-XJCsZ9SAIymdlBpEf5ARizHvn32t8Mr9stzV6nMVcn3utUYI1xSRxhaC29QZjS-C3haNSRPfQI_eBYzXCrwn5rl18Nw/s1700-nu-rw-lo-l85-e365/rev.jpg Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before… Read More "Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner"
Phishing Campaign Abuses eCards to Deploy RMM Tools
https://assets.infosecurity-magazine.com/webpage/og/fbf81513-5851-460d-9d28-bd3189285c84.jpg A six-month phishing operation has been tricking Windows and macOS users into installing legitimate remote monitoring and management (RMM) software through fake electronic greeting cards (eCards). According to new research published by Forescout on July 14, the campaign, which… Read More "Phishing Campaign Abuses eCards to Deploy RMM Tools"
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiSiBDO5j21gorWS-UjrLlDl0RzniibBPjfO4xfPBBLbH1yTQIB88G-hUBRtYNufYwkPpVjWWLu0GXk1TB7pv_x8KbQCbfsL5Ft8JlZLa6iZfvuHU-vKSPNq5Li-e9DtoOvZIOXPYmibx9uc_imnug4ZJUog31KwlA3YKmY8ghOpROVQR8mwPj9qb-1kA/s1700-nu-rw-lo-l85-e365/micro.jpg Swati KhandelwalSep 06, 2026Vulnerability / Network Security Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning, published… Read More "Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication"