Skip to content
Malware Injected into 6 npm Packages After Maintainer Tokens Stolen in Phishing Attack

Malware Injected into 6 npm Packages After Maintainer Tokens Stolen in Phishing Attack

Jul 20, 2025Ravie LakshmananDevOps / Threat Intelligence Cybersecurity researchers have alerted to a supply chain attack that has targeted popular npm packages via a phishing campaign designed to steal the project maintainers’ npm tokens. The… 

Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers

Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers

Jul 20, 2025Ravie LakshmananVulnerability / Threat Intelligence A newly disclosed critical security flaw in CrushFTP has come under active exploitation in the wild. Assigned the CVE identifier CVE-2025-54309, the vulnerability carries a CVSS score of… 

A surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations

A surveillance vendor was caught exploiting a new SS7 attack to track people’s phone locations

Security researchers say they have caught a surveillance company in the Middle East exploiting a new attack capable of tricking phone operators into disclosing a cell subscriber’s location. The attack relies on bypassing security protections…