theinfosecnews
CISA KEVCVE-2026-3502CVE-2026-5281CVE-2026-3055CVE-2025-53521CVE-2026-33634CISA KEVCVE-2026-3502CVE-2026-5281CVE-2026-3055CVE-2025-53521CVE-2026-33634
M
malware

Malicious npm Packages Target Strapi CMS with Multi-Stage Exploitation Payloads

Researchers discovered 36 malicious npm packages disguised as Strapi CMS plugins that exploit Redis and PostgreSQL, deploy reverse shells, harvest credentials, and install persistent implants. These packages threaten Node.js environments relying on npm dependencies, emphasizing the need for strict package vetting and credential management.

The Hacker News·13h ago·2 min read
Read full story
Allvulnerability78policy17malware17breach7apt6ransomware2
Aapt

TA416 Resurges with Targeted Attacks on European Government and Diplomatic Entities Since Mid-2025

Since mid-2025, the China-aligned threat actor TA416 has resumed targeting European government and diplomatic organizations after a two-year lull. The group employs spear-phishing, exploits Microsoft Office vulnerabilities, and uses multi-stage malware to conduct espionage. Detection and defense require patch management, email filtering, and endpoint monitoring.

The Hacker News·2d ago·2 min read
Bbreach

Supply Chain Attacks Linked to TeamPCP Amplified by ShinyHunters and Lapsus$ Involvement

Organizations have disclosed breaches stemming from TeamPCP's supply chain compromise, with threat actors ShinyHunters and Lapsus$ claiming involvement. These attacks exposed sensitive data through injected malicious code in software updates, affecting numerous enterprises. Affected users should audit software integrity, reset credentials, and enable multi-factor authentication.

Dark Reading·2d ago·2 min read