Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • Security Report
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: SUPPLY CHAIN

Threat Research

Technical Advisory: Immediately Patch Your VMware ESXi Servers Targeted by Opportunistic Threat Actors

February 8, 2023October 13, 2025 Securonix

Bitdefender researchers describe opportunistic threat actors abusing CVE-2021-21974 to target VMware ESXi, leveraging OpenSLP (port 427) for pre-auth remote code execution and deploying ESXiArgs ransomware against VM files. The advisory covers attack patterns,…

Read More
Threat Research

Open-source repository malware sows Havoc

February 7, 2023October 16, 2025 Securonix

ReversingLabs identified aabquerys, a malicious npm package that downloads second and third stage malware payloads to systems that have downloaded and run the npm package. This incident highlights growing open source supply chain risks in npm, PyPi, and GitHub…

Read More
Threat Research

#StopRansomware: Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities | CISA

February 6, 2023October 15, 2025 Securonix

The advisory outlines ongoing DPRK state-sponsored ransomware activity targeting Healthcare and Public Health Sector organizations and other critical infrastructure, detailing TTPs, IOCs, and cryptocurrency ransom payments. It also describes how actors acquire…

Read More
Threat Research

Supply Chain Attack by New Malicious Python Package, “web3-essential” | FortiGuard Labs

February 1, 2023October 13, 2025 Securonix

FortiGuard Labs detected a zero-day in a PyPI package named “web3-essential,” published by a newly joined user known as ‘Trexon’ on January 26, 2023. The package downloads and executes a Go-based binary to steal sensitive data and exfiltrate it via a Discord w…

Read More
Threat Research

Evolution of a Software Supply Chain Attacker

January 31, 2023October 14, 2025 CTI

Checkmarx researchers tracked a persistent threat actor they named PYTA27 who distributed multiple malicious Python packages to PyPI and GitHub, evolving from plain-text payloads to obfuscated and multi-stage stealers that target Discord and crypto-wallets. Th…

Read More
Threat Research

In-depth Analysis of the PyTorch Dependency Confusion – Aqua

December 27, 2022October 14, 2025 Aquasec

An attacker exploited a PyTorch-nightly dependency confusion by uploading a malicious Torchtriton package to PyPI, causing users to pull a counterfeit binary. The malware exfiltrates data via DNS to a domain controlled by the attacker, and the post explains th…

Read More
Threat Research

SentinelSneak: Malicious PyPI module poses as security software development kit

December 14, 2022October 17, 2025 Securonix

Two researchers uncovered a malicious PyPI package masquerading as a SentinelOne SDK client, named “SentinelSneak,” which actually implements a backdoor and data-exfiltration capabilities. The campaign highlights open-source software supply-chain risks, especi…

Read More
Threat Research

How 140k NuGet, NPM, and PyPi Packages Were Used to Spread Phishing Links

December 10, 2022October 14, 2025 Securonix

Checkmarx and Illustria uncovered a large-scale phishing operation that polluted NuGet, NPM, and PyPi with automated packages containing links to phishing campaigns. The effort involved tens of thousands of package names, phishing sites, and referral rewards, …

Read More
Threat Research

Phylum Detects Ongoing Typosquat/Ransomware Campaign in PyPI and NPM

December 9, 2022October 17, 2025 Securonix

Phylum reports an ongoing typosquatting campaign targeting Python and JavaScript developers on PyPI and NPM, delivering a ransomware payload when executed. The attacker publishes typosquatted packages (notably around the Python requests package) that fetch a l…

Read More
Threat Research

Probing Weaponized Chat Applications Abused in Supply-Chain Attacks

December 8, 2022October 17, 2025 Securonix

Trend Micro’s report reveals a supply-chain campaign that trojanized Comm100 and LiveHelp100 installers to deploy a JavaScript backdoor and multiple modules within Electron-based chat apps. The attackers used HTTP and WebSocket C2 channels to exfiltrate data, …

Read More
Threat Research

WASP Attack on Python — Polymorphic Malware Shipping WASP Stealer; Infecting Hundreds Of Victims

November 15, 2022October 13, 2025 Securonix

Researchers identify the WASP threat actor behind a Python package campaign that delivers a polymorphic WASP Stealer via PyPI and uses steganography to hide its payload. The malware targets Discord accounts, wallets, and other files, exfiltrating data through …

Read More
Threat Research

LofyGang – Software Supply Chain Attackers; Organized, Persistent, and Operating for Over a Year

October 7, 2022October 16, 2025 CTI

Checkmarx identified roughly 200 malicious NPM packages linked to the crime group LofyGang that abused typosquatting, sub-dependencies, and legitimate cloud services to distribute credential-stealing and Discord-targeted malware. The actors used Discord bots a…

Read More
Threat Research

CrowdStrike Falcon® Platform Identifies Supply Chain Attack via a Trojanized Comm100 Chat Installer – crowdstrike.com

September 28, 2022October 17, 2025 Securonix

CrowdStrike Falcon platform identified a supply chain attack tied to a trojanized Comm100 Live Chat installer, delivering a backdoor via a signed installer. The activity, with a suspected China nexus, involved a second-stage script, loader DLL, and multiple C2…

Read More
Threat Research

EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web

August 26, 2022October 16, 2025 Securonix

EvilProxy is a productized phishing service on the dark web that enables MFA bypass via reverse proxy and session cookie theft, expanding attacks against mainstream online services and software supply chains. It targets developers and end-users with campaigns …

Read More
Threat Research

Cyber Espionage in the South China Sea | Proofpoint US

August 23, 2022October 18, 2025 Securonix

Proofpoint’s Threat Research Team links a long-running TA423/Red Ladon espionage operation to a 2022 ScanBox phishing campaign targeting Australian government, offshore energy, and international entities in the South China Sea. The operation impersonates Austr…

Read More

Posts pagination

Previous 1 … 140 141 142 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
Twitter/X @TweetThreatNews
Facebook @Cybersecurity
LinkedIn Hendry Adrian

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.