en
GitHub Internal Breach: TeamPCP Exfiltrates 3,800 Repos via Poisoned VS Code Extension
Investigation into how TeamPCP used a poisoned VS Code Marketplace extension to pivot into developer workstations and exfiltrate 3,800 GitHub repositories.
en
Investigation into how TeamPCP used a poisoned VS Code Marketplace extension to pivot into developer workstations and exfiltrate 3,800 GitHub repositories.
es
Investigación de cómo TeamPCP utilizó una extensión de mercado de código VS envenenada para pivotar en estaciones de trabajo de desarrolladores y exfiltrate 3,800 repositorios GitHub.
en
How threat actors are actively weaponizing an unpatched stored XSS zero-day in Microsoft Exchange OWA to hijack mailbox session tokens.
es
Cómo los actores de la amenaza están armando activamente un XSS almacenado sin parche en Microsoft Exchange OWA para secuestrar fichas de sesión de correo.
en
How the Mini Shai-Hulud attack poisoned TanStack npm packages and bypassed SLSA Level 3 build provenance guarantees.
es
Cómo el ataque Mini Shai-Hulud envenenó paquetes TanStack npm y superó las garantías de procedencia de SLSA Level 3.
CVE Deep Dive
Technical exploit walkthrough of the Linux kernel Netfilter use-after-free vulnerability enabling local root privilege escalation.
Security Roundup
Weekly briefing: PAN-OS auth portal buffer overflow (root RCE), RubyGems 500+ malicious packages, and SHADOW-EARTH-053 espionage.
Threat Intel
In-depth threat intelligence report on SHADOW-EARTH-053 deploying ShadowPad, Godzilla webshells, and long-term espionage tradecraft.
CVE Deep Dive
Technical root cause and remediation for the unauthenticated administrative RCE flaw in Ivanti EPMM mobile device management systems.
Supply Chain
How campaign BufferZoneCorp flooded RubyGems with over 500 malicious packages using typosquatting and GemStuffer payload obfuscation.
CVE Deep Dive
Technical analysis of the CVSS 10.0 PAN-OS authentication portal buffer overflow granting unauthenticated remote root access.