Researchers discovered seven malicious npm packages that employ blockchain-based command-and-control (C2) infrastructure to deliver a Remote Access Trojan (RAT). This novel technique enables attackers to evade traditional detection methods and poses a significant threat to the software supply chain. Developers and organizations using npm should review their dependencies and take immediate action to mitigate risk.
A threat actor subgroup known as GoldenEyeDog has been tied to a security breach at certificate authority DigiCert, involving the theft of code-signing certificates. The stolen certificates could be used to sign malicious software, potentially bypassing security checks and undermining trust in digitally signed code. This incident highlights ongoing risks to the software supply chain and digital trust infrastructure.
A new malware strain called GoSerpent has been discovered targeting government entities and diplomats in Southeast Asia for espionage purposes. The malware is designed to steal sensitive data and maintain persistent access to compromised networks. This campaign highlights ongoing cyber threats against diplomatic and governmental targets in the region.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities catalog. This zero-day is already being actively exploited in attacks, prompting urgent calls for organizations to apply available patches immediately. The addition underscores the high risk of unpatched SharePoint servers.
A new macOS stealer named ClickLock aggressively terminates running applications every 210 milliseconds until the user types their password. This malware targets sensitive credentials and highlights evolving tactics in macOS threats. Users should be cautious of suspicious downloads and enforce strong security practices.
The European Union has ordered Google to allow rival app stores and search engines on Android devices, and to stop favoring its own services in search results. The landmark antitrust ruling aims to boost competition in mobile operating systems and online search. This decision could reshape how European users interact with their smartphones and access information.
More than 20 government websites were compromised and used as platforms to launch further cyberattacks. The hijacked sites redirected visitors to malicious content or distributed malware. This incident highlights the vulnerability of official domains and the risk of using them as trusted attack channels.
Researchers have discovered a new data injection attack targeting AI agents, allowing attackers to force misclicks or execute arbitrary commands. The attack exploits how AI agents process untrusted data from external sources. This matters because it exposes a critical vulnerability in autonomous AI systems that could be exploited to compromise security.
Zoom has released a security update for a critical vulnerability in its Windows client that could enable attackers to take over user accounts. The flaw, if exploited, could allow unauthorized access to sensitive data and control of the affected system. Users are urged to update their software immediately to prevent potential compromise.