Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
npm Supply Chain Attack: Six Malicious Packages Resolved C2 Servers via Ethereum Wallet — Detection and Remediation Guide
Security researchers have disclosed a campaign in which six malicious npm packages embedded a novel command-and-control (C2) resolution mech...
LiteLLM Supply Chain Attack via Trivy Compromise: 2,500+ Organizations Exposed — Detection and Remediation Guide
A Poisoned Python Package in the AI Stack LiteLLM — the popular open-source Python library used to normalize API calls across dozens of larg...
BdThemes Supply Chain Attack: Poisoned JSON Creates Rogue WordPress Admins — Detection and Remediation Guide
BdThemes Supply Chain Attack: Poisoned JSON Creates Rogue WordPress Admins WordPress site owners running plugins from vendor BdThemes need t...
Head Mare Exploits TrueConf Server Flaws to Push PhantomCore via Trojanized Installers — Detection and Remediation Guide
Introduction Kaspersky's incident response team has confirmed that the threat actor Head Mare is once again weaponizing vulnerabilities in u...
BdThemes Supply-Chain Compromise: Rogue WordPress Admin Accounts — Detection and Remediation Guide
BdThemes Supply-Chain Compromise: Rogue WordPress Admin Accounts — Detection and Remediation Guide A threat actor compromised the upstream i...
Malicious 'Solidity Pro' VS Code Extensions Steal Crypto Wallets and Credentials — Detection and Removal Guide
Malicious 'Solidity Pro' VS Code Extensions Steal Crypto Wallets and Credentials Security researchers have flagged a malicious Visual Studio...
Head Mare Hacktivists Trojanize TrueConf Client Installers: Detection and Hardening Guide for Exposed Video Conferencing Servers
Head Mare Hacktivists Trojanize TrueConf Client Installers: Detection and Hardening Guide The hacktivist group Head Mare has been compromisi...
Beacon CRM Breach: 1,500 Charities' Data Exfiltrated — Third-Party Detection and Response Playbook
A Vendor Breach With Your Name on the Breach Notification Beacon, a CRM platform serving the non-profit sector, has notified approximately 1...
TeamPCP Redis Attacks Since 2020: Detection and Hardening Guide for Internet-Exposed Redis Infrastructure
TeamPCP's Five-Year Run: From Redis Exploitation to Supply Chain Compromise New analysis has extended the operational history of the threat ...