Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
CVE-2026-76969: Critical @sap/cds-mtxs npm Vulnerability (CVSS 9.4) — Detection, Hunting, and Remediation Guide for SAP CAP Multitenant Applications
Introduction The NVD has published CVE-2026-76969, a CVSS 9.4 (CRITICAL) vulnerability in @sap/cds-mtxs, the npm package that provides multi...
DEV#POPPER npm RAT, Flying Eagle Android Botnet & APT28 Moobot Resurgence: OTX Pulse Analysis — Multi-Platform Detection Pack
DEVPOPPER npm RAT, Flying Eagle Android Botnet & APT28 Moobot Resurgence: Multi-Platform Threat Intelligence Bulletin Threat Summary Three c...
DEV#POPPER npm Supply Chain RAT, SectopRAT Fake Claude Installers & 19-Extension Wallet Drainer: OTX Pulse Analysis — Blockchain C2 & Credential Theft Detection Pack
Threat Summary A cluster of five OTX pulses published in late August 2026 reveals a converging trend across the infostealer and credential-t...
npm ClickFix Campaign: 24 Packages Abusing unpkg CDN to Host Fake Cloudflare CAPTCHA Pages — Detection and Response Guide
Introduction Threat actors have weaponized the npm ecosystem — not by poisoning developer build pipelines, but by using it as free, trusted ...
RedC2 4.0 Linux Implant Delivered via 14 Trojanized npm Packages — Detection and Remediation Guide
Introduction Cybersecurity researchers have uncovered a coordinated supply-chain campaign in which 14 trojanized npm packages — masquerading...
Miasma Worm v3 npm Supply-Chain Attack + Tomorrowland Credential-Harvesting Scam Network: OTX Pulse Analysis — Detection Pack
Miasma Worm v3 npm Supply-Chain Attack + Tomorrowland Credential-Harvesting Scam Network: OTX Pulse Analysis Two AlienVault OTX pulses publi...
npm Supply Chain Attack: Six Malicious Packages Resolved C2 Servers via Ethereum Wallet — Detection and Remediation Guide
Security researchers have disclosed a campaign in which six malicious npm packages embedded a novel command-and-control (C2) resolution mech...
NUL1DROPPER Slopsquatting Campaign + ChainDrop npm Worm: OTX Pulse Analysis — Supply Chain Credential Theft Detection Pack
NUL1DROPPER Slopsquatting Campaign + ChainDrop npm Worm: Supply Chain Credential Theft Threat Summary Two converging OTX pulses paint a clea...
Fake Roblox Cheats, npm RAT Clusters, and DarkSword Panels: Defending Against the Latest Malware Distribution Campaigns
Introduction The latest Security Affairs malware newsletter (Round 109) highlights three campaigns that should be on every SOC's radar this ...