Axios NPM Packages Compromised to Inject Malicious Codes in an Active Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has targeted Axios, one of the most heavily adopted HTTP clients within the JavaScript ecosystem, by introducing a malicious transitive dependency into the official npm …

Claude AI Discovers Zero-Day RCE Vulnerabilities in Vim and Emacs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic’s Claude AI successfully discovered zero-day Remote Code Execution (RCE) flaws in both Vim and GNU Emacs. The discoveries highlight a massive paradigm shift in bug hunting, demonstrating that AI …

Exposed Server Reveals TheGentlemen Ransomware Toolkit, Victim Credentials, and Ngrok Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A misconfigured server hosted on a Russian bulletproof hosting provider has exposed the complete operational toolkit of a TheGentlemen ransomware affiliate, including harvested victim credentials and plaintext authentication tokens used …

North Korean IT Worker Allegedly Used Stolen Identity and AI Resume in Job Application Scam

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A suspected North Korean operative tried to sneak into a remote job at a cybersecurity firm by using a stolen identity, a fake AI-generated resume, and a VoIP phone number. …

New ClickFix Variant Uses Rundll32 and WebDAV to Evade PowerShell Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and more dangerous version of the ClickFix attack technique has been found actively targeting Windows users. Unlike older versions that used PowerShell or mshta to run malicious commands, …

New Homoglyph Attack Techniques Help Cybercriminals Spoof Trusted Domains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have found a clever way to trick people by swapping real letters in website addresses with characters that look almost the same. These are called homoglyph attacks, and they …