Showing only posts in The Register. Show all posts.

Attackers targeting unpatched Cisco kit notice malware implant removal, install it again

Source

PLUS: Cyber-exec admits selling secrets to Russia; LastPass isn't checking to see if you're dead; Nation-state backed Windows malware; and more Infosec in brief Australia’s Signals Directorate (ASD) last Friday warned that attackers are installing an implant named “BADCANDY” on unpatched Cisco IOS XE devices and can detect …

Invisible npm malware pulls a disappearing act – then nicks your tokens

Source

PhantomRaven slipped over a hundred credential-stealing packages into npm A new supply chain attack dubbed PhantomRaven has flooded the npm registry with malicious packages that steal credentials, tokens, and secrets during installation. The packages appear safe when first downloaded, making them particularly difficult for security apps to identify.... [...]

« newer articles | page 27 | older articles »