Legacy Python bootstrap script creates domain takeover risk for multiple PyPI packages

November 28, 2025Ravi LakshmananMalware/vulnerabilities Cybersecurity researchers have discovered vulnerable code in a legacy Python package that could pave the way for a supply chain compromise of the Python Package Index (PyPI) through domain takeover attacks. Software supply chain security company ReversingLabs announced that it has discovered a “vulnerability” in a bootstrap file provided by a […]

North Korean hackers deploy 197 npm packages to spread latest OtterCookie malware

November 28, 2025Ravi LakshmananSupply chain attacks/malware The North Korean threat actors behind the Contagious Interview campaign have continued to flood the npm registry with 197 additional malicious packages since last month. According to Socket, these packages have been downloaded more than 31,000 times and are designed to provide a variant of OtterCookie that integrates functionality […]

Why organizations are turning to RPAM

November 28, 2025hacker newsEnterprise security/threat detection As IT environments become increasingly distributed and organizations embrace hybrid and remote work at scale, traditional perimeter-based security models and on-premises privileged access management (PAM) solutions are no longer sufficient. IT administrators, contractors, and third-party vendors now require secure access to critical systems from any location and any device […]

MS Teams Guest Access can remove Defender protection when users join an external tenant

November 28, 2025Ravi LakshmananEmail Security / Enterprise Security Cybersecurity researchers have uncovered a cross-tenant blind spot that allows attackers to bypass Microsoft Defender for Office 365 protections via the Guest Access feature in Teams. “When a user operates as a guest in another tenant, their protection is determined entirely by their hosting environment, not their […]

Bloody Wolf expands Java-based NetSupport RAT attacks in Kyrgyzstan and Uzbekistan

November 27, 2025Ravi LakshmananMalware/Social Engineering The threat actor known as Bloody Wolf is believed to be involved in a cyber attack campaign targeting Kyrgyzstan with the purpose of delivering the NetSupport RAT since at least June 2025. As of October 2025, the operation has expanded to include Uzbekistan, Group IB researchers Amirbek Kurbanov and Volen […]

Microsoft blocks unauthorized scripts in Entra ID logins with 2026 CSP update

November 27, 2025Ravi LakshmananWeb Security/Zero Trust Microsoft announced plans to improve the security of Entra ID authentication by blocking malicious script injection attacks starting in a year. Content Security Policy (CSP) updates are intended to enhance the Entra ID sign-in experience at ‘login.microsoftonline’.[.]com’ to only allow scripts to run from trusted Microsoft domains. “This update […]

AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories

Nov 27, 2025Ravie LakshmananCybersecurity / Hacking News Hackers have been busy again this week. From fake voice calls and AI-powered malware to huge money-laundering busts and new scams, there’s a lot happening in the cyber world. Criminals are getting creative — using smart tricks to steal data, sound real, and hide in plain sight. But […]

Gainsight expands list of affected customers following Salesforce security alert

November 27, 2025Ravi LakshmananRansomware/Cloud Security Gainsight has revealed that recent suspicious activity targeting its applications is impacting more customers than previously thought. The company said Salesforce initially provided a list of three affected customers, but as of November 21, 2025, it had “expanded to a larger list.” The company did not reveal the exact number […]

Shai-Hulud v2 campaign spreads from npm to Maven, exposing thousands of secrets

The second wave of the Shai-Hulud supply chain attack spilled over into the Maven ecosystem after compromising over 830 packages in the npm registry. The Socket Research Team said it has identified a Maven Central package named org.mvnpm:posthog-node:4.18.1 that includes the same two components related to Sha1-Hulud: the “setup_bun.js” loader and the main payload “bun_environment.js.” […]

Qilin ransomware turns South Korean MSP breach into “Korean leak” data heist for 28 victims

South Korea’s financial sector has been targeted by what is described as an advanced supply chain attack that led to the deployment of Qilin ransomware. “This operation combines the capabilities of Qilin, a leading Ransomware-as-a-Service (RaaS) group, with the potential involvement of North Korean state-affiliated actors (Moonstone Sleet), which utilized Managed Service Provider (MSP) compromises […]