Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Amazon Threat Intelligence attributed the September 2025 hijack of the npm packages debug and chalk to North Korea's Sapphire Sleet group with medium confidence, linking it to the same group behind the March 2026 axios compromise. The hijack involved a maintainer being phished through a lookalike npm domain, with wallet-draining scripts pushed into at least 18 packages carrying over 2 billion weekly downloads.
Amazon has attributed the September 2025 hijacking of the npm packages debug and chalk to North Korea's Sapphire Sleet hacking group. The attack involved phishing a maintainer through a fake npm domain and injecting wallet-draining scripts into 18 packages with over 2 billion weekly downloads.
A zero-day vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC) Software is being actively exploited, allowing attackers to access sensitive data using static credentials for a low-privileged account. The flaw, discovered by Horizon3.ai researcher Jimi Sebree, affects systems where the FMC management interface is exposed to the internet.
CISA added CVE-2026-20316 affecting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog following reports of zero-day exploitation. The vulnerability (CVSS 5.3) stems from static user credentials for a low-privileged account, allowing unauthenticated remote attackers to log in and access sensitive data.
CrowdStrike extends Falcon AIDR protection to Copilot Studio agents and Claude Code, safeguarding AI-powered development tools. The solution addresses AI-specific threats including prompt injection and data poisoning.
CrowdStrike announced that Falcon AIDR now protects Copilot Studio agents and Claude Code. This expansion enhances security for AI-powered development and automation environments.