organization · 3 records
StepSecurity

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Compromised MemTensor software packages are distributing a cross-platform credential-stealing malware.
1 outlet

Attackers target cPanel and WHM servers using compromised GitHub Actions repositories
Researchers report a large-scale campaign weaponizing compromised GitHub Actions repositories to target vulnerable cPanel and WebHost Manager servers for credential theft.
1 outlet Cyber read

Researchers identify SleeperGem malware targeting developer machines through malicious RubyGems packages
Cybersecurity researchers have identified a software supply chain attack called SleeperGem involving three malicious RubyGems packages that install persistence mechanisms on developer machine
1 outlet