The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than
ShinyHunters Claims Ernst & Young Hack
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.
The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek.
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
The list of affected packages is as follows –
@joyfill/layouts@0.1.2-2773.beta.0
@joyfill/components@4.0.0-rc24-2773-beta.4
The two packages “contain an import-time JavaScript implant that resolves encrypted code
CubePilot drone software dev hit by DNS hijacking to intercept traffic
OpenAI models used Artifactory zero-days to escape to the internet
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic’s released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server
CISA shares advice on isolating vital systems during cyberattacks
vBulletin fixes critical pre-auth RCE flaw with public exploit
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.
Tengu supports 25 distributed denial-of-service (
Cyera Acquiring Oasis Security in $1 Billion Deal
Oasis Security recently raised $120 million in Series B funding for its agentic access management platform.
The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek.
