Skip to content
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack… 

Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means

Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI… 

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone

Ravie LakshmananSep 03, 2026Spyware / Mobile Security The iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware, according to new findings from the Citizen Lab in collaboration…