Shai-Hulud Worm Unleashed in Ongoing NPM Supply Chain Attack
A sophisticated supply chain attack on the NPM registry has compromised hundreds of packages, deploying the self-replicating Shai-Hulud worm to steal cloud tokens and cryptocurrency.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,702 stories synthesized.
A sophisticated supply chain attack on the NPM registry has compromised hundreds of packages, deploying the self-replicating Shai-Hulud worm to steal cloud tokens and cryptocurrency.
PortSwigger Research has released WebSocket Turbo Intruder, a Burp Suite extension that enables high-speed fuzzing and automated testing of WebSocket connections, targeting a common blind spot in security testing.
Jenkins released Security Advisory 2025-09-17 addressing four vulnerabilities, including a high-severity HTTP/2 denial-of-service flaw in bundled Jetty.
The TeamPCP malware crew released the Shai-Hulud worm's source code on GitHub under MIT license, triggering an immediate wave of clones and copycat campaigns targeting npm developers — including the first reported clone-attack and subsequent npm package compromises.
Trend Micro has uncovered EvilAI, an ongoing campaign where attackers use AI-generated code to build trojanized apps that steal credentials and maintain persistent access across critical sectors worldwide.
GitLab released versions 18.3.2, 18.2.6, and 18.1.6 on September 10, 2025, patching multiple high-severity vulnerabilities including SSRF, DoS, and information disclosure flaws.
Trend Micro research details the tactics, techniques, and procedures of The Gentlemen ransomware group, which has targeted manufacturing, healthcare, and other critical sectors across 17 countries since August 2025.
The DFIR Report details an intrusion that connects three major ransomware operations—BlackCat/ALPHV, LockBit, and BlackSuit—through shared tooling and infrastructure.
PortSwigger Research discloses methods to bypass __Host and __Secure cookie prefix protections using Unicode whitespace and legacy parsing, affecting Django, ASP.NET, and Java-based servers.
Jenkins released a security advisory on September 3, 2025, disclosing four vulnerabilities in the Git client, global-build-stats, Jakarta Mail API, and OpenTelemetry plugins, urging administrators to update immediately.
GitLab released versions 18.3.1, 18.2.5, and 18.1.5 on August 27, 2025, fixing four medium-severity vulnerabilities including an unauthenticated GraphQL endpoint that exposes sensitive CI/CD variables.
PortSwigger Research has unveiled a novel CSS injection technique that uses inline style attributes and CSS conditionals to exfiltrate sensitive data from web pages without requiring external stylesheets.
PortSwigger Research publishes a detailed guide to help penetration testers and bug bounty hunters differentiate HTTP pipelining from genuine request smuggling vulnerabilities.
GitLab released versions 18.2.2, 18.1.4, and 18.0.6 on August 13, 2025, addressing three high-severity cross-site scripting vulnerabilities along with several medium-severity flaws in Community and Enterprise Editions.
Volexity has released GoStringExtractor, a new plugin for IDA Pro and Ghidra, and updated GoResolver with runtime type information recovery to aid analysts in reverse-engineering obfuscated Golang malware.
PortSwigger Research reveals new HTTP desync attack classes that compromised core infrastructure at Akamai, Cloudflare, and Netlify, arguing the protocol is fundamentally broken and must be replaced.
The Risky Business #799 podcast covers a wave of critical vulnerabilities and incidents, including a Microsoft SharePoint zero-day exploited in attacks, a Fortinet pre-auth SQL injection leading to RCE, and active exploitation of a Citrix Netscaler flaw.
GitLab released versions 18.2.1, 18.1.3, and 18.0.5 on July 23, 2025, fixing eight vulnerabilities including two high-severity cross-site scripting bugs in the Kubernetes proxy feature.
PortSwigger Research has released Repeater Strike, an AI-driven Burp Suite extension that automates the detection of Insecure Direct Object Reference vulnerabilities by analyzing manual testing traffic and scanning proxy history.
Researchers identified a new PHP-based variant of the Interlock ransomware group's RAT, shifting from JavaScript-based NodeSnake, used in widespread attacks since May 2025.
Jenkins released a security advisory covering 20 plugins, addressing vulnerabilities ranging from credential exposure and stored XSS to arbitrary value injection, with patches now available.
GitLab released versions 18.1.2, 18.0.4, and 17.11.6 on July 9, 2025, fixing four security vulnerabilities including a high-severity cross-site scripting issue (CVE-2025-6948) and three authorization bypass flaws.
The DFIR Report details an intrusion that began with a password spray attack against an internet-facing RDP server, culminating in the deployment of RansomHub ransomware across the victim's network.
GitLab released versions 18.1.1, 18.0.3, and 17.11.5 on June 25, 2025, fixing six security vulnerabilities, including a medium-severity flaw allowing unauthenticated file uploads to public projects.