Aggregator
【AI复盘】Palo Alto防火墙漏洞攻击
Rust-Written IronWorm Hits NPM Supply Chain
Brave Software releases Origin for a paid, bloat-free browsing experience
Hola Browser for Windows compromised to deliver cryptominer
China's TA4922 Expands Cybercrime Attacks Globally
Hackers Impersonate Ghidra, dnSpy, and SpiderFoot to Spread Malware via Fake Download Sites
Hackers are creating convincing fake websites that impersonate popular security tools to trick users into downloading malware. Instead of obvious phishing pages, these sites look almost identical to real project portals, complete with professional designs and links pointing to actual GitHub repositories. The moment a user clicks the download button, something very different happens behind […]
The post Hackers Impersonate Ghidra, dnSpy, and SpiderFoot to Spread Malware via Fake Download Sites appeared first on Cyber Security News.
Validated Compliance: VMware vDefend Conforms with NIST CSF, HIPAA and PCI DSS
VMware vDefend directly conforms to NIST CSF, HIPAA, and PCI DSS requirements, providing organizations with the critical controls needed to satisfy regulatory mandates and mitigate modern threats. Regulatory compliance has become a strategic imperative across all industry sectors due to a growing global focus on data privacy, supply chain transparency, and operational resilience. This urgency … Continued
The post Validated Compliance: VMware vDefend Conforms with NIST CSF, HIPAA and PCI DSS appeared first on VMware Security Blog.
binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts
A self-replicating worm has been quietly spreading across the npm registry using a method most security teams do not watch for. Instead of hiding inside package.json scripts, the attacker weaponized a tiny configuration file called binding.gyp to trigger malicious code the moment a developer runs npm install. The campaign hit dozens of packages across multiple […]
The post binding.gyp Supply Chain Attack Compromises Dozens of npm Packages Across Maintainer Accounts appeared first on Cyber Security News.