Flux RSS

— Sources secondaires
85articles RSS
7jReinitialiser
Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
Malware & RansomwareThe Hacker Newsil y a 7 jours

An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurrency miners and information stealers. "The campaign uses highly obfuscated VBScript files disguised as resume/CV documents, delivered through phishing emails," Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report shared

The Hidden Cost of Cybersecurity Specialization: Losing Foundational Skills
Outils & RechercheThe Hacker Newsil y a 7 jours

Cybersecurity has changed fast. Roles are more specialized, and tooling is more advanced. On paper, this should make organizations more secure. But in practice, many teams struggle with the same basic problems they faced years ago: unclear risk priorities, misaligned tooling decisions, and difficulty explaining security issues in terms the business understands. These challenges do not

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials
Threat IntelligenceThe Hacker Newsil y a 7 jours

Cybersecurity researchers have uncovered a new set of malicious npm packages that are designed to steal cryptocurrency wallets and sensitive data. The activity is being tracked by ReversingLabs as the Ghost campaign. The list of identified packages, all published by a user named mikilanjillo, is below - react-performance-suite react-state-optimizer-core react-fast-utilsa ai-fast-auto-trader

TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials
Malware & RansomwareThe Hacker Newsil y a 7 jours

Two more GitHub Actions workflows have become the latest to be compromised by credential-stealing malware by a threat actor known as TeamPCP, the cloud-native cybercriminal operation also behind the Trivy supply chain attack. The workflows, both maintained by the supply chain security company Checkmarx, are listed below - checkmarx/ast-github-action checkmarx/kics-github-action Cloud security