The activity is being tracked by ReversingLabs as the Ghost campaign. The list of identified packages, all published by a user named mikilanjillo, is below –
react-performance-suite
react-state-optimizer-core
react-fast-utilsa
ai-fast-auto-trader
react-performance-suite
react-state-optimizer-core
react-fast-utilsa
ai-fast-auto-trader
An out-of-bounds read vulnerability can be exploited remotely without authentication to read sensitive information from memory.
The post Critical Citrix NetScaler Vulnerability Poised for Exploitation, Security Firms Warn appeared first on SecurityWeek.
The hackers stole internal IDs, names, email addresses, and business partner IDs from an internal management system.
The post Mazda Says Employee, Partner Information Stolen in Cyberattack appeared first on SecurityWeek.
The FBI has published an alert describing the malware used by Iranian government hackers.
The post Stryker Says Malicious File Found During Probe Into Iran-Linked Attack appeared first on SecurityWeek.
checkmarx/ast-github-action
checkmarx/kics-github-action
Cloud security
CVE-2026-3055 (CVSS score: 9.3) – Insufficient input validation leading to memory overread
CVE-2026-4368 (CVSS score: 7.7) – Race condition leading to user
