Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Threat actors have been using a clever tactic to systematically gather sensitive information about organizations and their users through the GitHub API, according to a recent report from Datadog. This reconnaissance campaign has been ongoing for several months, with multiple overlapping campaigns leveraging “ghost accounts” – dormant user accounts that were registered years ago but … Read more

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

A new wave of sophisticated cyber attacks has been uncovered, targeting government agencies and organizations worldwide through a surprising vector: the Balochistan Police Portal in Pakistan. In what is being described as a multi-group espionage campaign, hackers have exploited vulnerabilities in this online platform to gain access to sensitive information, compromise systems, and launch further … Read more

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

A new and concerning threat has emerged on the npm package registry, one of the largest repositories of open-source code used in software development worldwide. A compromised version of Jscrambler’s 8.14.0 library was released, secretly installing a Rust-based infostealer malware during installation. The affected package, labeled as “jscrambler”, appears to be a legitimate library designed … Read more

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Threat actors have been systematically scanning and mapping GitHub organizations, repositories, and user accounts using a network of dormant “ghost” accounts. The abuse of GitHub’s API has been ongoing for several months, with multiple overlapping campaigns using leaked credentials and automated scanners to gather information. The activity, discovered by cybersecurity firm Datadog, involves exploiting publicly … Read more

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

A new wave of sophisticated cyberattacks has hit Pakistan’s Balochistan region, with hackers exploiting vulnerabilities in the province’s police portal to conduct espionage operations across multiple groups. The attacks, which have been linked to a well-coordinated campaign, highlight the growing threat of AI-powered vulnerability discovery and exploitation. The Balochistan Police Portal is an online platform … Read more

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

A critical vulnerability in the npm package jscrambler 8.14.0 has been exploited by attackers, installing a malicious Rust-based infostealer on victims’ systems during installation. The compromised package was available for download from npm’s official registry until July 7, when it was removed after being flagged by users. The vulnerability is particularly concerning due to the … Read more

My Stack Simulator, (Wed, Jul 8th)

A critical component of a computer’s memory has been compromised, leaving many organizations vulnerable to attack. The stack, a region where temporary data is stored, has been targeted by malicious actors looking to hijack program execution. The stack works like a physical pile of plates in your kitchen – new “plates” are added to the … Read more

Wireshark 4.6.7 Released, (Sat, Jul 11th)

Cybersecurity professionals and network administrators are breathing a sigh of relief as Wireshark, a popular network protocol analyzer, has just released its latest version – 4.6.7. This update addresses a pressing concern for anyone who relies on Wireshark to monitor and troubleshoot their network traffic: the presence of several security vulnerabilities. The update is notable … Read more

CISA looks to remedy ailments from big May credential leak

A major credential leak in May has prompted the US Cybersecurity and Infrastructure Security Agency (CISA) to take decisive action to strengthen its security posture. The agency’s swift response to the incident, which included revoking access to sensitive materials and analyzing log files to assess the scope of the breach, has been hailed as a … Read more

Armenian national pleads guilty to Ryuk ransomware attacks

A key player in a wave of devastating Ryuk ransomware attacks has been brought to justice, with an Armenian national pleading guilty to computer fraud and conspiracy. Karen Serobovich Vardanyan’s guilty plea marks a significant development in the ongoing effort to hold accountable those responsible for unleashing chaos on businesses and organizations worldwide. Between November … Read more