MemTensor Package Compromise Exposes Developers To Cross Platform Credential Stealer
Security researchers identify compromised MemTensor npm and PyPI packages delivering sckit malware designed to steal developer credentials and sensitive cloud data.
Security researchers identify compromised MemTensor npm and PyPI packages delivering sckit malware designed to steal developer credentials and sensitive cloud data.
Researchers have uncovered a supply chain attack targeting AI agents through trojanized skills that accumulated over 1.7 million installs and deployed credential stealing malware from GitHub.
The Gentlemen ransomware operation is strengthening its capabilities through the GentleKiller framework, enabling affiliates to disable hundreds of security processes and rapidly adopt new BYOVD exploits to evade detection.
Cybersecurity researchers warn that threat actors are exploiting a critical FortiClient EMS vulnerability to distribute credential stealing malware across managed endpoints using malicious PowerShell scripts.
Security researchers identify PCPJack credential stealer targeting cloud systems using five CVEs, enabling worm like propagation across Docker, Kubernetes, and other services.