New Shai Hulud Variant Hits Red Hat npm Packages
Researchers said that they found a Red Hat employee's GitHub account had been compromised and was used by threat actors to push malicious orphan commits directly to several repositories.
Lindsey O’Donnell-Welch is an award-winning journalist who strives to shed light on how security issues impact not only businesses and defenders on the front line, but also the daily lives of consumers.
Researchers said that they found a Red Hat employee's GitHub account had been compromised and was used by threat actors to push malicious orphan commits directly to several repositories.
The Silent Ransom Group, a data exfiltration and extortion actor, started posing as IT teams via phone calls and phishing emails sent to legal sector firms.
Law enforcement is increasingly targeting the “infrastructure layer” of cybercrime, rather than ransomware operators themselves.
An "unauthorized party” obtained a token with access to the Grafana Labs GitHub environment and downloaded Grafana’s codebase.
The vulnerability (CVE-2026-6973) exists in Ivanti Endpoint Manager Mobile (EPMM) is being exploited by threat actors.
Deniss Zolotarjovs, 35, of Moscow, Russia, was a member of a ransomware group called Karakurt, which was led by the former operators of Conti.