24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Malware Spreads Through npm Packages, Targeting Cloudflare Users A disturbing trend has emerged in the world of cybersecurity, as hackers have exploited a vulnerability in the popular package manager npm to spread malware through 24 compromised packages. The malicious code uses a clever trick to impersonate Cloudflare’s CAPTCHA pages, potentially putting thousands of users at … Read more

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

A massive wave of attacks, dubbed “Mirage2FA,” has struck over 4,500 companies in the US and EU, compromising sensitive login credentials and leaving a trail of exposed identities in its wake. The campaign’s operators have leveraged a clever manipulation of Microsoft 365 login flows to bypass multi-factor authentication (MFA) protections, allowing them to gain unauthorized … Read more

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Cybersecurity researchers have uncovered a critical flaw in the Marimo Notebook app that could allow attackers to execute malicious commands on users’ devices even when they are editing sensitive files. The vulnerability, which affects both Android and iOS versions of the app, highlights the importance of prioritizing security in popular productivity tools. The issue arises … Read more

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

Cybersecurity giants WhatsApp have rolled out a significant update to its mobile app, introducing multiple passkeys for phishing-resistant sign-ins on both iOS and Android devices. This move comes as part of an ongoing effort to protect users from increasingly sophisticated cyber threats. The new feature allows users to generate and store multiple passkeys – essentially … Read more

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A malicious webpage can secretly feed fake data into local AI models, compromising their accuracy and potentially leading to catastrophic consequences. This alarming vulnerability affects any system running NVIDIA’s NemoClaw framework, which is used in various applications, including healthcare, finance, and autonomous vehicles. The attack works by manipulating a user’s browser into submitting malicious input … Read more

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

A Wave of Phishing Attacks Exploits npm Package Vulnerability, Putting Users’ Data at Risk A concerning trend has emerged in the cybersecurity landscape, as hackers are exploiting a vulnerability in the npm package ecosystem to host fake Cloudflare CAPTCHA pages on unpkg mirrors. This clever tactic is designed to bypass security measures and trick users … Read more

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

A sprawling cyberattack campaign, dubbed “Mirage2FA,” has compromised the login credentials of over 4,500 companies across the United States and Europe. The attackers have been exploiting vulnerabilities in Microsoft 365’s authentication flows to gain unauthorized access to corporate networks, raising concerns about the security posture of these organizations. At its core, Mirage2FA involves a sophisticated … Read more

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

A Critical Flaw in Marimo Notebook Exposes Sensitive Data and Privileges, Threatening Millions of Users Marimo Notebook, a popular note-taking app, has been found vulnerable to a critical flaw that could allow attackers to execute malicious commands on users’ devices. The vulnerability, which affects millions of users worldwide, was discovered in the app’s edit mode, … Read more

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

WhatsApp’s Latest Security Upgrade Aims to Protect Users from Sophisticated Phishing Attacks In a significant move to bolster user security, WhatsApp has rolled out an innovative feature that enables users to create multiple passkeys for phishing-resistant sign-ins across both iOS and Android devices. This long-awaited upgrade comes as a response to the growing threat of … Read more

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A Critical Vulnerability in NVIDIA’s NemoClaw Exposes Local AI Models to Malicious Webpage Poisoning Researchers have discovered a critical flaw in NVIDIA’s NemoClaw, an open-source framework for building and managing local artificial intelligence (AI) models. The vulnerability allows malicious webpages to inject poisoned data into these models, potentially compromising sensitive information and disrupting AI operations. … Read more