800+ npm Packages and Thousands of GitHub Repos Compromised
24
Nov
2025

800+ npm Packages and Thousands of GitHub Repos Compromised

A massive resurgence of the Sha1-Hulud supply chain malware has struck the open-source ecosystem, compromising over 800 npm packages and…

New EtherHiding Technique Uses Web Attacks to Deploy Malware and Rotate Payloads
24
Nov
2025

New EtherHiding Technique Uses Web Attacks to Deploy Malware and Rotate Payloads

A new era of web-delivered malware has arrived with EtherHiding, a technique that fundamentally reshapes how attackers distribute and rotate…

19,000 Repos Hit: New Shai Hulud Worm Wave Steals Developer Secrets
24
Nov
2025

Shai Hulud npm Worm Infects 19,000 Packages in Major Supply Chain Attack – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More

The Shai Hulud npm worm has re-emerged, launching an aggressive new attack on the software development world. This worm, which…

This campaign aims to tackle persistent security myths in favor of better advice
24
Nov
2025

This campaign aims to tackle persistent security myths in favor of better advice

Some cybersecurity advice has been around for ages: Frequently change passwords, avoid public Wi-Fi. But most experts say a lot…

Harvard
24
Nov
2025

Harvard University discloses data breach affecting alumni, donors

Harvard University disclosed over the weekend that its Alumni Affairs and Development systems were compromised in a voice phishing attack,…

Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper
24
Nov
2025

Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper

India-aligned threat group Dropping Elephant has launched a sophisticated multi-stage cyberattack targeting Pakistan’s defense sector using a Python-based remote access…

Malicious PyPI Package Used by Hackers to Steal Users’ Crypto Information
24
Nov
2025

Malicious PyPI Package Used by Hackers to Steal Users’ Crypto Information

Cybersecurity researchers have uncovered a sophisticated supply-chain attack targeting Python developers through a malicious package distributed via the Python Package…

New ‘IndonesianFoods’ worm floods npm with 100,000 packages
24
Nov
2025

Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub

Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the…

APT35 Hacker Groups Internal Documents Leak Exposes their Targets and Attack Methods
24
Nov
2025

APT35 Hacker Groups Internal Documents Leak Exposes their Targets and Attack Methods

In October 2025, a significant breach exposed the internal workings of APT35, also known as Charming Kitten, a cyber unit…

Amazon Is Using Specialized AI Agents for Deep Bug Hunting
24
Nov
2025

Amazon Is Using Specialized AI Agents for Deep Bug Hunting

As generative AI pushes the speed of software development, it is also enhancing the ability of digital attackers to carry…

PoC Published for W3 Total Cache Flaw Exposing 1M+ Sites to RCE
24
Nov
2025

PoC Published for W3 Total Cache Flaw Exposing 1M+ Sites to RCE

Security researchers have published a proof-of-concept exploit for a critical remote code execution vulnerability in W3 Total Cache, one of…

True Cybersecurity Story: How FreakyClown Robs Banks
24
Nov
2025

True Cybersecurity Story: How FreakyClown Robs Banks

24 Nov True Cybersecurity Story: How FreakyClown Robs Banks Posted at 08:43h in Blogs by Taylor Fox This week in…