Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Beta versions of two npm packages in the @joyfill namespace were compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The implant executes when Node.js loads the CommonJS package entry point and uses a multi-blockchain resolver structure (Tron, Aptos, BNB Smart Chain) for command-and-control, linking it to the PolinRider threat cluster and Contagious Interview campaign.
This FAQ details a coordinated cyberattack on US water utilities that impacted at least 12 states. It covers operational effects, attack indicators, and defensive measures for exposed infrastructure.
This FAQ details a coordinated cyberattack on US water utilities that impacted at least 12 states. It covers operational effects, attack indicators, and defensive measures for exposed infrastructure.
A coordinated cyber attack disrupted water systems across more than 30 Minnesota communities.
A coordinated cyberattack targeted water and wastewater systems across more than 30 Minnesota communities on July 26-27, 2026, with attribution pending investigation. The attack aligns with Iranian-affiliated PLC exploitation activity documented in CISA Advisory AA26-097A, which expanded to include Schneider Electric and Siemens devices and noted exploitation of CVE-2021-22681.
A coordinated cyberattack targeted water and wastewater systems in over 30 Minnesota communities. The timing aligns with recent activity against exposed PLCs.