Security News

Nine-Year-Old npm Packages Hijacked to Exfiltrate API Keys via Obfuscated Scripts
2025-03-28 06:06

Cybersecurity researchers have discovered several cryptocurrency packages on the npm registry that have been hijacked to siphon sensitive information such as environment variables from compromised...

Hijacked Microsoft web domain injects spam into SharePoint servers
2025-03-27 23:11

The legacy domain for Microsoft Stream was hijacked to show a fake Amazon site promoting a Thailand casino, causing all SharePoint sites with old embedded videos to display it as spam. [...]

Don't want your Kubernetes Windows nodes hijacked? Patch this hole now
2025-01-24 15:00

SYSTEM-level command injection via API parameter *chef's kiss* A now-fixed command-injection bug in Kubernetes can be exploited by a remote attacker to gain code execution with SYSTEM privileges...

13,000 MikroTik Routers Hijacked by Botnet for Malspam and Cyberattacks
2025-01-21 12:46

A global network of about 13,000 hijacked Mikrotik routers has been employed as a botnet to propagate malware via spam campaigns, the latest addition to a list of botnets powered by MikroTik...

Over 4,000 backdoors hijacked by registering expired domains
2025-01-08 17:34

Over 4,000 abandoned but still active web backdoors were hijacked and their communication infrastructure sinkholed after researchers registered expired domains used for commanding them. [...]

New details reveal how hackers hijacked 35 Google Chrome extensions
2024-12-31 18:54

New details have emerged about a phishing campaign targeting Chrome browser extension developers that led to the compromise of at least thirty-five extensions to inject data-stealing code,...

Cybersecurity firm's Chrome extension hijacked to steal users' data
2024-12-27 15:39

At least five Chrome extensions were compromised in a coordinated attack where a threat actor injected code that steals sensitive information from users. [...]

Ultralytics AI model hijacked to infect thousands with cryptominer
2024-12-06 18:54

The popular Ultralytics YOLO11 AI model was compromised in a supply chain attack to deploy cryptominers on devices running versions 8.3.41 and 8.3.42 from the Python Package Index (PyPI) [...]

1000s of Palo Alto Networks firewalls hijacked as miscreants exploit critical hole
2024-11-22 21:27

PAN-PAN! Intruders inject web shell backdoors, crypto-coin miners, more Thousands of Palo Alto Networks firewalls were compromised by attackers exploiting two recently patched security bugs. The...

Experts Uncover 70,000 Hijacked Domains in Widespread 'Sitting Ducks' Attack Scheme
2024-11-14 17:36

Multiple threat actors have been found taking advantage of an attack technique called Sitting Ducks to hijack legitimate domains for using them in phishing attacks and investment fraud schemes for...