Aggregator
Trivy供应链攻击触发CanisterWorm 在47个 npm 包中自传播
Oracle 紧急修复 Identity Manager 和 Web Services Manager 中的严重RCE漏洞
$30 IP-KVM Flaws Could Give Attackers BIOS-Level Control Across Enterprise Networks
A recent security assessment by researchers has uncovered nine severe vulnerabilities across four popular low-cost IP-KVM devices. These flaws uncovered by Eclypsium allow attackers to gain complete, BIOS-level control over connected systems, effectively bypassing all operating system security controls and Endpoint Detection and Response (EDR) agents. Compromising a Keyboard, Video, and Mouse (KVM) device gives […]
The post $30 IP-KVM Flaws Could Give Attackers BIOS-Level Control Across Enterprise Networks appeared first on Cyber Security News.
“龙虾”一句话险些让Meta裸奔,360用AI监管AI守住防线
Global Crackdown Dismantles 4 Botnets Behind Major DDoS Attacks
【安全圈】地缘冲突下加密货币“雪崩”,比特币跳水,20万人爆仓血本无归!
【安全圈】晋中网安部门破获一起非法获取公民个人信息案
【安全圈】为博眼球使用 AI 造谣“烟花厂爆炸致 2 死 2 伤”,男子被依法处罚
上周关注度较高的产品安全漏洞(20260316-20260322)
CNVD漏洞周报2026年第11期
【非虫系列】打包更优惠!安卓软件开发与逆向分析(开发篇+工具篇)
新型木马绕过 Chrome 加密,无注入窃取浏览器主密钥
首届 PolarisCTF 招新赛正式启幕
安卓逆向基础知识之frida Hook
Сканер уязвимостей, который сам стал главной уязвимостью. Ироничная история взлома Trivy.
FBI warns of Handala hackers using Telegram in malware attacks
三星 Galaxy S26 支持 AirDrop
New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts
A new wave of supply chain attacks is hitting the npm ecosystem through a self-propagating malware campaign known as CanisterWorm. The threat, linked to a group tracked as “TeamPCP,” compromises legitimate publisher namespaces and pushes poisoned package versions, effectively turning trusted developer tools into silent delivery mechanisms for credential-stealing code. CanisterWorm first came to public […]
The post New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts appeared first on Cyber Security News.