Aggregator
Proton Claims 300 Million Records Compromised So Far This Year
解决了一个大麻烦
PhantomRaven Attack Involves 126 Malicious npm Packages with Over 86,000 Downloads Hiding Malicious Code
A sophisticated malware campaign targeting developers has been operating since August 2025, deploying 126 malicious npm packages that have collectively accumulated over 86,000 downloads. The attack, now identified as PhantomRaven, has been actively harvesting npm authentication tokens, GitHub credentials, and CI/CD pipeline secrets from developers across the globe while employing advanced detection evasion techniques that […]
The post PhantomRaven Attack Involves 126 Malicious npm Packages with Over 86,000 Downloads Hiding Malicious Code appeared first on Cyber Security News.
Кофе за $590 из экскрементов животных: учёные раскрыли химию самого дорогого кофе в мире
ThreatsDay Bulletin: DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs Rising
Ex-Defense contractor exec pleads guilty to selling cyber exploits to Russia
CISA:DELMIA 工厂软件漏洞已遭利用
VSCode 供应链攻陷:12个恶意扩展窃取源代码并开启远程控制
Critical RediShell RCE Vulnerability Threatens 8,500+ Redis Deployments Worldwide
A critical security vulnerability in Redis’s Lua scripting engine has left thousands of database instances vulnerable to remote code execution attacks. The RediShell RCE vulnerability, tracked as CVE-2025-49844, was publicly disclosed in early October 2025 by cloud security firm Wiz, revealing a use-after-free memory corruption issue that enables attackers to escape the Lua sandbox and […]
The post Critical RediShell RCE Vulnerability Threatens 8,500+ Redis Deployments Worldwide appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.