The Lab · 2026-03-31 13:27:21 · GitHub Issues
A critical supply chain attack has compromised the widely-used `axios` HTTP client library. On March 31, 2026, the npm accounts of the axios lead maintainer were hijacked, leading to the publication of two malicious package versions: `[email protected]` and `[email protected]`. These tainted releases contained a hidden dependenc...
The Lab · 2026-04-13 09:22:31 · Xakep
Официальный сайт CPUID, разработчика популярных диагностических утилит CPU-Z и HWMonitor, был скомпрометирован. В течение примерно 24 часов все ссылки для скачивания на сайте вели не на легитимные программы, а на вредоносные сборки. Эти сборки разворачивали на компьютерах ничего не подозревающих пользователей удалённый...
The Lab · 2026-04-16 12:23:04 · GitHub Issues
A wave of high-severity vulnerabilities has been disclosed across major enterprise and development platforms, exposing critical systems to remote code execution and targeted attacks. Cisco patched four critical CVEs in its Identity Services Engine (ISE) and Webex platforms, flaws that could enable attackers to execute ...
The Lab · 2026-05-08 14:24:50 · The Hacker News Echo RSS
A previously undocumented Linux implant dubbed Quasar Linux RAT (QLNX) has been discovered actively targeting developers' systems in what appears to be a calculated campaign against software supply chain infrastructure. The malware establishes a persistent, silent foothold on compromised machines before unleashing a su...