Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article details a sophisticated macOS malvertising campaign linked to North Korea that uses fake update pages to trick users into executing malware via the ClickFix technique. The campaign employs blockchain-hosted command-and-control and aims to steal cryptocurrency and deploy malicious extensions.
Amazon has linked several high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers, specifically involving the Debug and Chalk packages. These attacks highlight ongoing threats to the open-source supply chain.
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers.
Broadcom has released security updates to address five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that could enable attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Users are urged to apply the patches promptly.
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
This article is a personal narrative about a challenging hike in Shenandoah National Park, describing the steep climbs and rock scrambles. It is not related to cybersecurity.