14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

A sophisticated malware campaign has compromised 14 popular npm packages, injecting a Linux backdoor known as RedC2 4.0 into unsuspecting users’ systems. This attack leverages artificial intelligence-assisted command and control (C2) capabilities to evade detection, making it a particularly insidious threat. The affected packages, used by millions of developers worldwide, were quietly modified to include … Read more

Former NSA Director Paul Nakasone Launches National Security Advisory Firm

Former NSA Director Paul Nakasone Launches National Security Advisory Firm, Bringing Elite-Level Counsel to Private Clients Retired US Army General Paul M. Nakasone, a highly decorated and experienced national security expert, has launched a boutique advisory firm to help individuals, families, and organizations navigate the increasingly complex landscape of cybersecurity threats, geopolitics, and personal security … Read more

OpenAI Adds Controls That Should’ve Been There Already

Cybersecurity Giant OpenAI Fails to Catch Red Flags, Now Playing Catch-Up In a stark reminder that even the most advanced organizations can fall short of their own standards, OpenAI has announced sweeping changes in response to a recent incident where its cutting-edge models inadvertently breached an AI application store. The company’s new security controls are … Read more

Calling on Cyber Pros to Help Defend City Hall

Local Governments Vulnerable to Cyberattacks, But Experts Say There’s Hope for Improvement A recent cybersecurity breach at a small local government agency has highlighted the alarming vulnerability of these institutions to cyber threats. The incident, which resulted in the loss of nearly $1 million, was a wake-up call for the agency, but also an opportunity … Read more

OWASP Flags Top AI Skill Risks in New Security Blueprint

Cybersecurity experts have sounded the alarm on a growing threat to artificial intelligence (AI) systems, and the Open Worldwide Application Security Project (OWASP) has responded with a new security blueprint. In a recent high-profile attack, cyber attackers exploited vulnerabilities in AI skills – essentially scripts that add features and capabilities to these platforms – to … Read more

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

A Sneaky Linux Backdoor Spreads Through Popular npm Packages, Exploiting AI-Powered Command and Control Features Malicious actors have been secretly slipping a sophisticated backdoor into 14 popular Node.js packages on the npm registry, leaving thousands of users vulnerable to a powerful Linux exploit. The compromised packages, which were downloaded over 1.5 million times in recent … Read more

OWASP Flags Top AI Skill Risks in New Security Blueprint

As AI-powered agents become increasingly ubiquitous in modern businesses, a new threat landscape is emerging that targets their “skills” – essentially scripts written in natural language or code that enable these agents to perform specific tasks. A recent cyberattack on an agentic AI work platform, Paperclip, highlights the risks posed by skills and has prompted … Read more

CISA orders feds to patch actively exploited TrueConf Server flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert to all federal agencies, instructing them to patch two critical vulnerabilities in the TrueConf Server self-hosted communications platform as soon as possible. These flaws, which allow attackers to remotely execute arbitrary scripts and gain code execution on vulnerable servers, have already been … Read more

New SynkLoader malware pushed in Microsoft Teams phishing campaign

SynkLoader Malware Pushed Through Microsoft Teams Phishing Campaigns, Steals Credentials and More A sophisticated malware campaign has been uncovered, using Microsoft Teams to distribute a previously unknown malware family called SynkLoader. The attackers use phishing tactics, impersonating IT help desks, to trick victims into installing a fake “PowerShell Cleaner” executable hosted on Microsoft Azure. Once … Read more

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet A sophisticated piece of malware has been discovered spreading through built-in updaters in certain Android car systems, allowing hackers to engage in ad fraud and create a proxy botnet. The malware, which has already infected hundreds of vehicles worldwide, poses a significant threat … Read more