North Korean Hackers Infiltrate npm Registry with 197 Malicious Packages to Distribute Enhanced OtterCookie Malware In a significant escalation of cyber threats, North Korean state-sponsored […]
Month: November 2025
Legacy Python Scripts Risk Domain Takeover; PyPI Packages Vulnerable to Supply Chain Compromise
Legacy Python Bootstrap Scripts Pose Domain Takeover Threat in Multiple PyPI Packages Cybersecurity researchers have identified a significant vulnerability within legacy Python packages that could […]
Sophisticated Malware Shai Hulud v2 Exploits GitHub Actions, Compromising 834 Software Packages
Shai Hulud v2: A Sophisticated Malware Campaign Exploiting GitHub Actions to Compromise Software Supply Chains The software development community is currently facing a significant threat […]
Abandoned iCalendar Domains Create Security Risks for Millions of Devices
Abandoned iCalendar Sync Domains Pose Security Risks to Millions of Devices In today’s digital age, calendar applications are integral to managing both personal and professional […]
Cybercriminal Group Targets Zendesk with Over 40 Typosquatted Domains to Harvest Credentials
Cybercriminals Exploit Zendesk with Over 40 Deceptive Domains A sophisticated cyberattack campaign has been launched by the group known as Scattered Lapsus$ Hunters, targeting Zendesk, […]
Legacy Python Packages Threaten Supply Chains via Domain Takeover Risks, Analysts Warn
Legacy Python Packages Pose Supply Chain Risks Through Domain Takeover Vulnerabilities In the ever-evolving landscape of software development, legacy code can often become a hidden […]
Shai Hulud 2.0 Malware Breaches 1,200 Organizations, Exfiltrates Sensitive CI/CD Data
Shai Hulud 2.0: A Sophisticated Malware Compromises Over 1,200 Organizations In late November 2025, a formidable malware campaign known as Shai Hulud 2.0 emerged, infiltrating […]
Cyberattack Cripples IT Systems of Three London Councils, Affecting Public Services
Cyberattack Disrupts Services Across Three London Councils In late November 2025, a significant cyberattack targeted the shared IT infrastructure of three central London councils: the […]
Microsoft Strengthens Entra ID Security by Blocking External Scripts in Sign-In Process
Article Title: Microsoft Enhances Entra ID Security by Blocking External Scripts in Sign-In Process In a significant move to bolster cybersecurity, Microsoft has announced an […]
Poland Arrests Russian for Cyberattacks on Local Organizations, Highlights National Cybersecurity Efforts
Poland Arrests Russian Citizen for Cyberattacks on Local Organizations In a significant move to bolster national cybersecurity, Polish authorities have detained a Russian national accused […]