News
-
Suspicious Polyfill login prompts appear on Toshiba and Muji sites
Toshiba and Muji warned that suspicious sign-in screens appeared on parts of their websites in Japan this week, with the prompts tied to polyfill.io. The companies said users who entered credentials should change passwords.
-
New npm supply chain worms hit 50-plus packages, steal secrets
Two npm supply chain attacks spread a Rust information stealer and a worm across dozens of packages, targeting developer secrets, cloud credentials and AI tool configurations. Researchers said the malware used GitHub and npm features to keep propagating.
-
Researchers link new OP-512 cluster to IIS server espionage campaign
Researchers found a new China-linked threat cluster, OP-512, targeting Microsoft IIS servers with a custom web shell framework. The activity used timestomping, self-reporting shells and attempted privilege escalation on a legacy Windows Server 2016 host.
-
WFP says breach exposed data of about 600,000 Gaza households
The World Food Programme said a breach of its Gaza self-registration system exposed personal details of about 600,000 households. The agency suspended the platform, but said aid delivery and existing registrations would continue.
-
PCPJack hijacks 230 cloud servers for covert SMTP relay network
PCPJack hijacked 230 cloud servers tied to AWS, Google Cloud and Microsoft Azure to run a covert SMTP relay network, according to Hunt.io. The infrastructure used Sliver and Chisel tools and was still active when found.
-
DentaQuest says breach affected part of network, leak tied to 2.6 million accounts
DentaQuest said a security incident exposed data tied to 2.6 million accounts after a breach linked to ShinyHunters. The leaked records included names, contact details, government IDs and health insurance information.
-
iFood confirms data breach affecting 1.2 million users in Brazil
iFood said a December data breach exposed the personal details of 1.2 million users in Brazil, including CPF numbers, but not passwords or payment data. The company and hackers dispute the scale of the incident.
-
China-linked TA4922 widens phishing attacks to Europe and South Africa
China-linked TA4922 has expanded phishing campaigns from East Asia to organizations in the U.K., Germany, Italy and South Africa, using malware such as Atlas RAT, RomulusLoader and SilentRunLoader, according to a Proofpoint technical analysis.
-
Fake open-source tool sites used to push malware through gated redirects
Researchers say fake sites impersonating open-source tools such as Ghidra and dnSpy are using gated redirects to push malware, including Remus Stealer, AnimateClipper and SessionGate, after users click download buttons.
-
Hackers spent months inside stock exchange executive’s Outlook inbox
Unknown attackers spent at least five months inside a senior stock exchange executive’s Outlook mailbox, copying messages in small batches and routing them through Dropbox and OneDrive in what researchers described as espionage.









