One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package
N-able warns of N-central auth bypass flaw exploited in attacks
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per
Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) appeared first on SecurityWeek.
Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 billion
The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud.
The post Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 billion appeared first on SecurityWeek.
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
Inside the Underground Business of BTMOB RAT
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from
River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
The bank holding company was hacked in June, but the investigation into the incident continues.
The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek.
