Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation
Malicious npm packages have been discovered distributing infostealer malware that propagates like a worm across developer ecosystems. According to researchers at Socket, impacted packages execute malicious code during installation to harvest sensitive data like cloud credentials, CI/CD tokens, and cryptocurrency wallets. The malware exfiltrates this data using HTTPS webhooks and Internet Computer Protocol (ICP) endpoints. Furthermore, it extracts npm tokens to inject code and republish compromised packages, demonstrating a concerning capability for self-propagation. This highlights the growing sophistication of supply chain attacks targeting developers, emphasizing the need for robust securing of development workflows and secrets.
Read the original article here
Actively Exploited SharePoint Spoofing Bug Continues to Threaten Over 1,300 Instances
Over 1,300 internet-exposed Microsoft SharePoint servers remain vulnerable to an actively exploited zero-day spoofing flaw tracked as CVE-2026-32201. Despite patches being issued during a recent Patch Tuesday, fewer than 200 online instances have been updated to fix the vulnerability. According to The Shadowserver Foundation, nearly half of these exposed servers are located in North America, with successful exploitation potentially allowing threat actors to expose and modify sensitive data. The persistence of this unpatched vulnerability poses significant data security risks for exposed organizations, reinforcing the importance of timely patch management.
Read the original article here
UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW Malware
A newly identified threat cluster known as UNC6692 is leveraging social engineering tactics via Microsoft Teams to deploy a novel malware family dubbed SNOW. The attackers pose as internal IT support personnel to deceive employees into downloading and executing the malicious payload on their corporate devices. By exploiting the inherent trust users place in enterprise communication platforms like Teams, the threat actors bypass traditional email security gateways. This trend underscores the critical need for continuous security awareness training and strict verification protocols for internal IT support requests.
Read the original article here
Vercel Breached via Compromised Third-Party AI Tool
Cloud deployment platform Vercel recently suffered a security breach stemming from a compromised third-party AI tool that allowed attackers to access its internal systems. The incident originated from a tool named Context.ai, which enabled an attacker to hijack a Vercel employee’s Google Workspace account. By exploiting this access, the threat actor enumerated and viewed some non-sensitive Vercel environments and customer environment variables. This supply chain incident highlights the growing security risks associated with granting broad permissions to third-party AI extensions in enterprise environments.
Read the original article here
Formbook Malware Campaign Uses Multiple Obfuscation Techniques to Avoid Detection
A newly identified cyber campaign is leveraging stealthy infection techniques to distribute Formbook, a longstanding infostealer malware, to Microsoft Windows devices. Cybersecurity researchers at WatchGuard have detected two distinct phishing operations targeting organizations globally. One campaign relies on dynamic-link library (DLL) sideloading to execute malicious code unnoticed, while the other hides its payload within highly obfuscated JavaScript and PDF files. These attacks illustrate how established malware families continue to innovate their delivery methods, requiring security teams to enhance their detection capabilities against script execution and DLL anomalies.
Read the original article here
