Category Security

Manifest Confusion Attack Opens Door to Malware

July 5, 2023Ravi LakshmananSupply Chain / Software Security The npm registry for the Node.js JavaScript runtime environment is the so-called obvious confusion This attack could allow threat actors to hide malware in project dependencies or execute arbitrary scripts during installation.…

Mexican Hacker Unleashes Android Malware on Global Banks

Security researcher Pol Till has identified a Mexico-based hacker known as Neo_Net as the mastermind behind a string of cyberattacks targeting global banks. According to Thill’s findings, published by SentinelOne after a malware research challenge in partnership with vx-underground, Neo_Net…

Over Two-Thirds of FortiGate Firewalls Still at Risk

About 69% of FortiGate firewalls affected by the recently discovered FortiOS vulnerability remain unpatched, according to Bishop Fox security researchers. This flaw (CVE-2023-27997) could lead to remote code execution (RCE). Patched by Fortinet in mid-June. For more information about this…