Mini Shai-Hulud Attack Targets SAP npm Packages, Exposes Developer Credentials 

A new cyberattack called “Mini Shai-Hulud” has been discovered and is linked to a group known as TeamPCP. This attack mainly targets software packages used in SAP development environments. Instead of directly hacking systems, the attackers chose a smarter approach by compromising trusted tools. These tools are used daily by developers, which makes the attack … Continued

Poisoned Ruby Gems and Go Modules Target CI/CD Pipelines for Credential Theft 

A new cybersecurity threat has been discovered where attackers are using fake open-source packages to target developers and automated systems. These attacks involve malicious Ruby gems and Go modules that were uploaded online and made to look like trusted libraries. The main goal of this campaign is to steal sensitive credentials and gain unauthorized access … Continued

BlueNoroff’s Fake Zoom Calls Are Turning Victims Into Cyberattack Tools 

A new cyberattack campaign has been discovered involving BlueNoroff, which is known for targeting financial systems. In this case, the group is focusing on people working in the cryptocurrency industry. The attackers are using fake online meetings to trick victims into trusting them. These meetings appear to be real business discussions. However, everything is actually … Continued

When Pandemic Research Became a Cyber Target: Silk Typhoon Extradition Case

A Chinese national accused of being part of a major hacking group has been extradited to the United States in a case linked to cyberattacks during the COVID-19 pandemic. The group, known as Silk Typhoon, has been associated with large-scale cyber espionage activities targeting sensitive data across the world. These attacks mainly focused on organizations … Continued

Behind the CAPTCHA: How SMS Traps and Traffic Tools Are Powering Global Crypto Fraud 

A new cybercrime campaign has been discovered where attackers are using fake CAPTCHA pages to trick people into sending costly SMS messages without realizing it. At the same time, researchers have identified more than 120 large-scale campaigns powered by Keitaro, which are spreading cryptocurrency scams and malware globally. This combination shows how cybercriminals are blending … Continued

Newsletter line