npm
02
Sep
2023

Yes, there’s an npm package called @(-.-)/env and some others like it

Strangely named npm packages like -, @!-!/-, @(-.-)/env, and –hepl continue to exist on the internet’s largest software registry. While not all of…

Promptmap ChatGPT
02
Sep
2023

Prompt Injection Attacks on ChatGPT Instances

Prompt injection refers to a technique where users input specific prompts or instructions to influence the responses generated by a…

Person being extorted
02
Sep
2023

New ‘YouPorn’ sextortion scam threatens to leak your sex tape

A new sextortion scam is making the rounds that pretends to be an email from the adult site YouPorn, warning…

Chisel Android Malware
02
Sep
2023

CISA Report on Notorious Chisel Android Malware

With the rise of new technological innovations and security mechanisms, threat actors are also upgrading their skills and evolving rapidly. …

Google Chrome
02
Sep
2023

Chrome extensions can steal plaintext passwords from websites

A team of researchers from the University of Wisconsin-Madison has uploaded to the Chrome Web Store a proof-of-concept extension that can…

North Korea's Hacker Group Deploys Malicious in PyPI Repository
02
Sep
2023

North Korea’s Hacker Group Deploys Malicious in PyPI Repository

ReversingLabs spotted “VMConnect” in early August, a malicious supply chain campaign with two dozen rogue Python packages on PyPI. It’s…

Nmap Version 7.94 Released
02
Sep
2023

Nmap 7.94 Released: What’s New!

The latest version of Nmap, 7.94, was released on its 26th birthday. The most significant upgrade was the migration of…

SapphireStealer .NET Malware
02
Sep
2023

SapphireStealer Malware Capable of Stealing Sensitive

SapphireStealer is an open-source information stealer that may be utilized for obtaining sensitive information, such as corporate credentials, which are frequently…

Chinese Smishing Triad Gang Hits US Users in Extensive Cybercrime Attack
02
Sep
2023

Chinese Smishing Triad Gang Hits US Users in Extensive Cybercrime Attack

Triad cleverly impersonates postal/delivery services like Royal Mail or USPS to trap unsuspecting US citizens in its newly detected smishing…

Social engineering attacks target Okta customers to achieve a highly privileged role
02
Sep
2023

Social engineering attacks target Okta customers to achieve a highly privileged role

Social engineering attacks target Okta customers to achieve a highly privileged role Pierluigi Paganini September 02, 2023 Identity services provider…

Dating Apps And Sites: Mitigating Chargebacks In 2023
02
Sep
2023

What Are The Cybersecurity Risks Of Smart Home Devices?

by Zac Amos Smart home devices have become highly popular in a relatively short period. While this proliferation of connected…

API6:2023 Unrestricted Access to Sensitive Business Flows
02
Sep
2023

API6:2023 Unrestricted Access to Sensitive Business Flows

Welcome to the 7th post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a…