<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1076912843267184&amp;ev=PageView&amp;noscript=1">

News (4)

October 4, 2023

The Hacker News: Rogue npm Package Deploys Open-Source Rootkit in New Supply Chain Attack

A new deceptive package hidden within the npm package registry has been uncovered deploying an open-source rootkit called r77, marking the first time a rogue package has delivered rootkit functionality.
October 2, 2023

SC Media: Why software teams have to change their focus from vulnerabilities to malware

Nearly 90% of companies report they have detected a security issue in their software supply chain in the last 12 months.
September 1, 2023

SC Media: VMConnect campaign linked to North Korea’s Lazarus Group

Three newly discovered malicious Python packages posted to the Python Package Index (PyPI) are now believed to be part of the VMConnect campaign and have also been tied to the North Korean Lazarus Group.
August 31, 2023

Bleeping Computer: Lazarus hackers deploy fake VMware PyPI packages in VMConnect attacks

North Korean state-sponsored hackers have uploaded malicious packages to the PyPI (Python Package Index) repository
August 25, 2023

Dark Reading: Luna Grabber Malware Targets Roblox Gaming Devs

Roblox gaming developers are lured in by a package that claims to create useful scripts to interact with the Roblox website