On April 22, for roughly 90 minutes, a malicious version of Bitwarden CLI appeared on npm. Version 2026.4.0 contained a credential-stealing payload that executed an obfuscated loader and harvested AWS, Azure, GCP, GitHub, and npm tokens from any developer machine that ran npm install. The attackers reached Bitwarden’s npm publishing path through a compromised GitHub…
Tag: appeared
AI, Exploits, Global Security News
Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability
Shortly after the authentication-bypass flaw was disclosed multiple proof-of-concept exploits appeared, and one researcher claims there’s been zero-day activity for at least a month.
Global Security News, malware
Alleged RedLine malware developer extradited to United States
A man has appeared in federal court in Austin, Texas, after being extradited to the United States to face charges related to his alleged role as a key developer of the notorious RedLine malware. Read more in my article on the Hot for Security blog.
Global Security News
DHS CISO, deputy CISO exit amid reported IT leadership overhaul
The post DHS CISO, deputy CISO exit amid reported IT leadership overhaul appeared first on CyberScoop.
Global Security News
AlpenShield
The post AlpenShield appeared first on SOC Prime.
AI, Endpoint, Exploits, Global Security News, Risk Management
Fake AI Chrome Extensions Exposed 260,000 Users, Targeting Gmail
More than 260,000 Chrome users installed what appeared to be helpful AI productivity tools… only to unknowingly grant remote servers deep access to their browser activity. LayerX researchers identified a coordinated campaign of 30 fake AI assistant extensions that used embedded iframes and backend-controlled logic to extract data and maintain persistent access. “We found over…
AI, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, Risk Management
260K Users Exposed in AI Extension Scam
More than 260,000 Chrome users installed what appeared to be helpful AI productivity tools — only to unknowingly grant remote servers deep access to their browser activity. LayerX researchers identified a coordinated campaign of 30 fake AI assistant extensions that used embedded iframes and backend-controlled logic to extract data and maintain persistent access. “We found…
