Miasma Worm Returns as RAT-First npm Attack With Automatic Propagation Disabled

Four AsyncAPI packages previously affected by the Shai-Hulud: The Second Coming campaign have been compromised again, with new malicious releases delivering a RAT-focused build of the Miasma worm. The impacted versions are @asyncapi/generator 3.3.13.3.13.3.1, @asyncapi/generator-components 0.7.10.7.10.7.1, @asyncapi/generator-helpers 1.1.11.1.11.1.1, and @asyncapi/specs…

Attackers Distribute Password Attacks Across Fictional OAuth Apps to Evade SOC Alerts

Attackers are increasingly abusing spoofed OAuth application identifiers to enumerate Microsoft Entra ID accounts, test credentials, and fragment authentication activity across hundreds of thousands or millions of fictional applications. The technique exploits how Entra ID processes the client_id parameter in…

Malicious Jscrambler NPM Packages Released

A recent supply chain attack targeting Jscrambler resulted in the publication of several malicious versions of its popular NPM package over the weekend. This article has been indexed from CyberMaterial Read the original article: Malicious Jscrambler NPM Packages Released

Pentagon Suspends CMMC Phase 2 Cyber Rules

The Department of War has officially suspended the implementation of the Cybersecurity Maturity Model Certification (CMMC) phase two requirements, initiating a comprehensive 60-day program review. This article has been indexed from CyberMaterial Read the original article: Pentagon Suspends CMMC Phase…

Google Dialogflow CX Rogue Agent Flaw Fixed

A severe security vulnerability in Google’s Dialogflow CX, named “Rogue Agent,” could have allowed attackers with edit permissions on a Code Block-enabled agent to compromise other agents within the same Google Cloud project. This article has been indexed from CyberMaterial…

Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads

Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investigation links these operations into…