Welcome to your weekly threat intelligence briefing. The cybersecurity landscape shifted dramatically between May 25 and May...
supply chain attack
Microsoft Threat Intelligence researchers recently uncovered an active security breach targeting modern software developer pipelines. Specifically, a...
Urgent Alert for DevOps Engineers Microsoft security analysts recently identified an active threat vector targeting modern software...
Open-source software repositories remain a top target for modern cybercriminals. Recently, Socket’s Threat Research Team uncovered a...
Security researchers at Socket have uncovered a coordinated attack targeting PHP Composer packages by hiding malicious JavaScript...
A major software supply-chain storm is brewing in the PHP ecosystem. Security firm Socket has exposed a...
The notorious threat syndicate tracking under the moniker TeamPCP, an adversarial collective primarily renowned for orchestrating supply-chain...
Grafana Labs has broken its silence regarding a targeted corporate cyberattack that culminated in the theft of...
A massive and highly coordinated supply chain assault is currently ripping through the JavaScript developer ecosystem. Security...
A brief but dangerous supply chain attack briefly hijacked the official Visual Studio Code marketplace, targeting over...
Security researchers have exposed a highly stealthy attempted intrusion that weaponized an open-source framework into a potent...
In a sophisticated supply-chain attack, attackers compromised the official JDownloader website between May 6 and May 7,...
Security researchers are sounding the alarm on a highly resourceful new campaign dubbed “GemStuffer.” Uncovered by Socket’s...
A critical security vulnerability has been found in WebdriverIO, a popular open-source test automation framework used for...
The software supply chain has just weathered another high-impact assault. The Socket Threat Research team has uncovered...
When millions of users rely on a popular utility, the implicit trust placed in its official download...
A highly sophisticated software supply chain attack has compromised tens of thousands of developer workstations and CI/CD...
In a calculated move that signals the expansion of state-sponsored threats into open-source repositories, researchers at Kaspersky...
A previously undocumented Linux remote access trojan (RAT) has been exposed for its surgical precision in targeting...
Kaspersky has uncovered a sophisticated supply chain attack targeting DAEMON Tools, the widely used disk imaging software....