Category: TheHackerNews

20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack
09
Sep
2025

20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack

Sep 09, 2025Ravie LakshmananCryptocurrency / Software Security Multiple npm packages have been compromised as part of a software supply chain…

Salt Typhoon Cyber Espionage
09
Sep
2025

45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage

Sep 09, 2025Ravie LakshmananCyber Espionage / Telecom Security Threat hunters have discovered a set of previously unreported domains, some going…

GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies
08
Sep
2025

GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies

Sep 08, 2025Ravie LakshmananSupply Chain Attack / API Security Salesloft has revealed that the data breach linked to its Drift…

GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms
08
Sep
2025

GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms

Sep 08, 2025Ravie LakshmananMalvertising / Encryption Cybersecurity researchers have detailed a new sophisticated malware campaign that leverages paid ads on…

You Didn't Get Phished — You Onboarded the Attacker
08
Sep
2025

You Didn’t Get Phished — You Onboarded the Attacker

When Attackers Get Hired: Today’s New Identity Crisis What if the star engineer you just hired isn’t actually an employee,…

Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign
06
Sep
2025

Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign

A threat actor possibly of Russian origin has been attributed to a new set of attacks targeting the energy sector…

Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys
06
Sep
2025

Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys

Sep 06, 2025Ravie LakshmananSoftware Security / Cryptocurrency A new set of four malicious packages have been discovered in the npm…

Critical Sitecore Vulnerability Under Active Exploitation
05
Sep
2025

CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation

Federal Civilian Executive Branch (FCEB) agencies are being advised to update their Sitecore instances by September 25, 2025, following the…

TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations
05
Sep
2025

TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations

The threat actor behind the malware-as-a-service (MaaS) framework and loader called CastleLoader has also developed a remote access trojan known…

SAP S/4HANA Critical Vulnerability CVE-2025-42957 Exploited in the Wild
05
Sep
2025

SAP S/4HANA Critical Vulnerability CVE-2025-42957 Exploited in the Wild

Sep 05, 2025Ravie LakshmananVulnerability / Enterprise Security A critical security vulnerability impacting SAP S/4HANA, an Enterprise Resource Planning (ERP) software,…

Automation Is Redefining Pentest Delivery
05
Sep
2025

Automation Is Redefining Pentest Delivery

Sep 05, 2025The Hacker NewsPentesting / Security Operations Pentesting remains one of the most effective ways to identify real-world security…

VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages
05
Sep
2025

VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages

Sep 05, 2025Ravie LakshmananMalware / Cryptocurrency Cybersecurity researchers have flagged a new malware campaign that has leveraged Scalable Vector Graphics…