Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Laravel-Lang Supply Chain Attack: Detecting and Remediating Malicious Credential Stealer Packages
Laravel-Lang Supply Chain Attack: Detecting and Remediating Malicious Credential Stealer Packages Introduction The open-source ecosystem fac...
Malicious Nx Console VS Code Extension: Detection, Credential Theft, and Remediation
Malicious Nx Console VS Code Extension: Detection, Credential Theft, and Remediation Introduction A critical supply chain attack has comprom...
Mini Shai Hulud: @antv npm Supply Chain Attack & CI/CD Credential Theft
Introduction The software supply chain has suffered a significant blow with the discovery of a malicious campaign targeting the @antv npm ec...
TanStack npm Supply Chain Attack: Detecting Nx Console Compromise & GitHub Token Theft
Introduction GitHub has confirmed that the breach of 3,800 internal source code repositories was the direct result of a sophisticated supply...
GitHub Breach via Malicious Nx Console VS Code Extension: Detection & Hardening
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension: Detection and Remediation Introduction On Wednesday, GitHu...
Fox Tempest MSaaS Takedown: Detecting Abuse of Microsoft Artifact Signing
On Tuesday, Microsoft announced the disruption of a sophisticated Malicious Software-Signing-as-a-Service (MSaaS) operation orchestrated by ...
Shai-Hulud Supply Chain Attack: Detection and Remediation for 600 Compromised npm Packages
Introduction A massive supply-chain attack campaign, dubbed "Shai-Hulud," has flooded the Node Package Manager (npm) registry with over 600 ...
Storm-2949: Cloud-Wide Identity Breach Detection and Hardening Guide
Introduction Storm-2949 has redefined the scope of cloud intrusions, proving that a single compromised identity can serve as a master key fo...
Malicious npm Packages: Infostealers and Phantom Bot DDoS — Detection and Removal Guide
Introduction Security researchers have identified a fresh wave of malicious packages targeting the npm ecosystem, specifically designed to c...