Weaponized AI Assistants & Credential Thieves


Just weeks after the s1ngularity attack weaponized AI assistants, the NPM ecosystem was rocked by a far more dangerous threat: a self-propagating worm named Shai-Hulud.

In a sobering demonstration of this rapid escalation in attack techniques, the worm has compromised over 187 packages, including several developer-facing tools published by cybersecurity firm CrowdStrike. These two distinct events paint a clear picture of a new and accelerating threat to the open-source supply chain. Let’s break down this evolution.

Read more…
Source: Trend Micro


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Command Injection and Local File Inclusion in Grafana: CVE-2024-9264

    October 24, 2024

    The SonicWall Capture Labs threat research team became aware of a critical vulnerability in Grafana, assessed its impact and developed mitigation measures. Grafana is a multi-platform open-source analytics and visualization solution that can produce charts, graphs and alerts according to the data. Identified as CVE-2024-9264, Grafana versions 11.0.x, 11.1.x and 11.2.x allows an attacker with ‘viewer’ ...

  • The Crypto Game of Lazarus APT: Investors vs. Zero-days

    October 23, 2024

    On May 13, 2024, Kaspersky consumer-grade product Kaspersky Total Security detected a new Manuscrypt infection on the personal computer of a person living in Russia. Since Lazarus rarely attacks individuals, this piqued Kaspersky researchers interest and they decided to take a closer look. The researchers discovered that prior to the detection of Manuscrypt, Kaspersky technologies also ...

  • LinkedIn bots and spear phishers target job seekers

    October 23, 2024

    Microsoft’s social network for professionals, LinkedIn, is an important platform for job recruiters and seekers alike. It’s also a place where criminals go to find new potential victims. Like other social media platforms, LinkedIn is no stranger to bots attracted to special keywords and hashtags. Think “I was laid off”, “I’m #opentowork” and similar phrases that ...

  • VMWare vCenter Server CVE-2024-38812 DCERPC Vulnerability

    October 23, 2024

    CVE-2024-38812 is a critical heap-overflow vulnerability identified in VMware vCenter Server’s implementation of the DCERPC (Distributed Computing Environment/Remote Procedure Call) protocol. This flaw allows a malicious actor with network access to the vCenter Server to send specially crafted packets, potentially leading to remote code execution (RCE). The vulnerability, classified under CWE-122 (Heap-based Buffer Overflow), arises when ...

  • Russia says ‘unprecedented’ cyber attack hits foreign ministry amid BRICS summit

    October 23, 2024

    The Russian Foreign Ministry was targeted by a severe cyber attack on Wednesday, coinciding with the major BRICS summit taking place in the country, spokeswoman Maria Zakharova said. Earlier Zakharova said that the ministry had been targeted by a large-scale distributed denial-of-service attack (DDoS). “A massive cyberattack from abroad began this morning on the infrastructure of ...

  • Cybersecurity Awareness Month: Recognizing Phishing Attacks

    October 23, 2024

    In conjunction with the U.S. Cybersecurity and Infrastructure Agency (CISA) and the National Cybersecurity Alliance (NCA), SonicWall is participating in Cybersecurity Awareness Month this October to spread awareness about key issues in cybersecurity. In their last blog, SonicWall mentioned that while password hygiene and multifactor authentication are both crucial, they can be easily foiled by a ...