Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Amazon has identified a North Korean hacker group, tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces, as responsible for multiple supply chain attacks targeting popular Node Package Manager (NPM) libraries. The group compromised widely used packages like axios, debug, chalk, and typo-crypto by socially engineering maintainers and injecting malicious code into updates.
Amazon has shared new findings about a DPRK-linked threat actor targeting open source software libraries. The actor compromised several popular NPM packages, including axios, debug, and chalk.
Amazon Threat Intelligence has identified a DPRK-linked threat actor behind recent compromises of popular NPM libraries. The analysis reveals how generative AI is altering malicious software packages and targeting AI-based code systems.
Amazon Threat Intelligence has identified a North Korean hacker group, tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces, behind a series of supply chain attacks targeting popular Node Package Manager (NPM) libraries. The group compromised widely used packages such as axios, debug, chalk, and typo-crypto by socially engineering trusted maintainers and publishing malicious updates.
Broadcom's Symantec SSE has been recognized as a quadruple leader in KuppingerCole's Zero Trust Leadership Compass, validating its approach to Zero Trust security. This recognition underscores the importance of independent analyst validation in reinforcing enterprise security strategies.
Broadcom has been named a quadruple leader in KuppingerCole's Zero Trust Leadership Compass. Independent analyst validation reinforces Symantec SSE's approach to Zero Trust security.