Injective SDK on npm infected with cryptocurrency wallet stealer

A critical security vulnerability has been discovered in a popular Node Package Manager (npm) package, allowing hackers to steal cryptocurrency wallet private keys and mnemonic seed phrases. The Injective SDK project’s GitHub repository was compromised, leading to the publication of a malicious package on npm that has already been downloaded over 50,000 times. The affected … Read more

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

Cloud Bucket Hijacking, Windows LPE Chain, and Global Fraud Bust Exposed in Recent Threat Landscape Updates A series of alarming security threats has been exposed in recent days, with hackers targeting cloud storage buckets, exploiting a previously unknown vulnerability in Windows systems, and engaging in large-scale global fraud. In this article, we’ll take a closer … Read more

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

A New Windows Backdoor Emerges, Wiping Data and Spying on Users In a worrying development, researchers have uncovered a sophisticated backdoor malware targeting Windows systems, capable of wiping entire disks, spreading fake ransomware, and installing spyware. The new threat, discovered by experts at cybersecurity firm ESET, has been dubbed “GigaWiper.” If you use a Windows … Read more

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

A worrying trend is unfolding on GitHub, where attackers are using dormant accounts to blend in and map corporate organizations’ internal structures. Researchers have uncovered evidence of malicious activity involving these seemingly inactive profiles, which raises significant concerns about the potential for insider threats or compromised credentials. The issue highlights the importance of monitoring even … Read more

Microsoft to retire the OWA Light client in Exchange Server

Microsoft has announced plans to retire the lightweight version of its Outlook Web App email client, known as OWA Light, from Exchange Server. The decision marks a significant shift in Microsoft’s focus towards modernizing its web-based email experience, and it will likely have far-reaching implications for organizations that still rely on outdated systems. For those … Read more

Microsoft expects more Windows security updates from AI-discovered flaws

Microsoft is ramping up its efforts to bolster Windows security through artificial intelligence (AI) as the company relies increasingly on AI-powered tools to uncover vulnerabilities in its codebase. As a result, users can expect to see more frequent and extensive security updates in the coming months. The acceleration of vulnerability discovery thanks to advances in … Read more

New Helix vishing group emerges in SharePoint data theft attacks

A new threat group called Helix has emerged, using sophisticated tactics to steal sensitive data from SharePoint environments. The group’s modus operandi involves voice phishing, device code phishing, and multi-factor authentication abuse to gain access to victim accounts. Once inside, Helix operators quickly register a new authenticator app for persistence, browse and enumerate SharePoint, and … Read more

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

A New Era of Cyber Threats Emerges with Cloud Bucket Hijacking and AI-Powered Vulnerability Discovery The latest threat landscape is proving more complex than ever, with a surge in sophisticated attacks targeting cloud storage buckets and exploiting software vulnerabilities discovered by artificial intelligence models. In this new era of cyber threats, even the most seemingly … Read more