Výsledky hledání

téma: malware× v celém archivu zrušit filtry

189 karet z 192 položek · strana 3 z 4 CZ · EN/orig

1

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Research by: Jaromír Hořejší (@JaromirHorejsi) Key points StopAndProtect is a newly identified operation that combines file encryption with data theft. The criminals abuse thousands of hacked WordPress websites as their infrastructure – using them to spread the malware, control infected machines, and store stolen documents, screenshots, and activity logs (records created by malware to track its actions, progress, or status during execution). Operational security (OPSEC) failures by the…

WordPress IL

tg: varování tg: rozbor tp: malware tp: phishing tp: ransomware tp: únik dat

· Check Point Research · Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

1

SPOJENO PŘES CVE Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress

Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.

KEV ✓ EPSS 0.97 CVSS 9.0 CVE-2026-60137 CVE-2026-63030 WordPress CZ US AT FR

tg: zneužíváno tg: rozbor tg: návod tg: přehled tp: malware tp: ransomware

· NÚKIB · Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress · Cisco Talos · Don’t swing at everything · Elastic Security · wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution · CERT.at · Kritische Sicherheitslücken in WordPress - Updates verfügbar · CERT-FR – alerty · Multiples vulnérabilités dans WordPress (20 juillet 2026)

1

New Android malware lets criminals use your bank card in real time

Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.” NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together. So, instead of stealing your physical bank card, the attackers capture NFC activity on an infected mobile phone and relay it in…

Google finance US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Malwarebytes Labs · New Android malware lets criminals use your bank card in real time

2

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

In this article Pre-encryptionEncryptionPost-encryptionDefending against DeadLock ransomwareIndicators of compromise Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion…

doprava výroba a průmysl US

tg: rozbor tp: malware tp: ransomware

· Microsoft Security Blog · DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

2

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of keyv, a widely used key-value storage library. The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to. The reach of this compromise is significant: keyv alone received over 600 million downloads last month, with related packages compounding…

keyv flat-cache cacheable-request cacheable US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Elastic Security · Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of keyv, a widely used key-value storage library. The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to. The reach of this compromise is significant: keyv alone received over 600 million downloads last month, with related packages compounding…

keyv flat-cache cacheable-request cacheable US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Elastic Security · Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

2

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

In this article Activity overviewHow ClickFix works Campaign overviewClickFix moved from open pages to fingerprinting gatesThe fingerprinting gateMitigation and protection guidanceIndicators of compromise (IOC)ReferencesLearn more Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS), through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side…

Apple US

tg: varování tg: rozbor tp: malware tp: phishing

· Microsoft Security Blog · From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

In this article Attack chain overviewMitigation and protection guidanceIndicators of compromise (IOC)Microsoft Defender XDR detectionsAdvanced hunting queriesLearn more Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. The malicious releases contain a Mini Shai-Hulud…

npm US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Microsoft Security Blog · ChainDrop supply chain compromise: Anatomy of a self-propagating worm

1

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 

In this article What is device isolation?Case study: QNETAttack chain overviewMITRE ATT&CK techniques observedReferencesLearn more Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints. At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload–a classic living-off-the-land (LOL) technique that often…

Microsoft obchod US

tg: incident tg: rozbor tg: propagace tp: malware tp: ransomware

· Microsoft Security Blog · 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 

3

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In this article The CaptiveCrunch campaignStorm-2945 and Midnight BlizzardCaptiveCrunch tradecraft and toolingHow to protect against CaptiveCrunch activityMicrosoft Defender detections and hunting guidanceIndicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some…

Microsoft veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: identita tp: špionáž

· Microsoft Security Blog · CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

We know you’re tired of hearing how every vendor is going to finally help you solve alert fatigue. Well, one way we’re improving alert fatigue is from a slightly different angle, better prevention at the endpoint. Because stopping more at the endpoint means fewer alerts ever raised. We have three endpoint enhancements, all contributing to better endpoint prevention: To be even more proactive about Bring Your Own Vulnerable Driver (BYOVD) attacks, we’re continuously monitoring public vulnerable…

Elastic US

tg: novinka v produktu tg: propagace tp: malware

· Elastic Security · What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

We know you’re tired of hearing how every vendor is going to finally help you solve alert fatigue. Well, one way we’re improving alert fatigue is from a slightly different angle, better prevention at the endpoint. Because stopping more at the endpoint means fewer alerts ever raised. We have three endpoint enhancements, all contributing to better endpoint prevention: To be even more proactive about Bring Your Own Vulnerable Driver (BYOVD) attacks, we’re continuously monitoring public vulnerable…

Elastic US

tg: novinka v produktu tg: propagace tp: malware

· Elastic Security · What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support

1

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”.msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert tunneling to establish command-and-control (C2) communications.This RAT never touches the network directly — it…

US

tg: rozbor tp: malware tp: ransomware

· Cisco Talos · Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

2

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs found a new Contagious Interview campaign, tracked as REF9403, hiding malware inside SVG image files using steganography. To our knowledge, this specific infection chain has not been previously documented. We found it after the DPRK-aligned group targeted our own community Slack workspace with a fake job posting and a "coding challenge" project. Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet…

US

tg: varování tg: rozbor tp: malware tp: phishing tp: dodavatelský řetězec tp: špionáž

· Elastic Security · New North Korean campaign uses fake coding interviews to steal developer credentials

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs found a new Contagious Interview campaign, tracked as REF9403, hiding malware inside SVG image files using steganography. To our knowledge, this specific infection chain has not been previously documented. We found it after the DPRK-aligned group targeted our own community Slack workspace with a fake job posting and a "coding challenge" project. Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet…

US

tg: varování tg: rozbor tp: malware tp: phishing tp: identita tp: špionáž

· Elastic Security · New North Korean campaign uses fake coding interviews to steal developer credentials

4

Begun, the Patch Wars have

Welcome to this week’s edition of the Threat Source newsletter. We all knew, to some degree or another, that this summer was going to a hot mess. I don’t mean FIFA drama or record setting heat waves. I mean the slow but steady momentum that AI frontier models were accruing for vulnerability research. If you were like me, and guesstimating exactly when that shoe would drop, my money was on the middle of summer. And... well, friends, I hate to say it, but I was right. This July’s Patch Tuesday is…

Microsoft US

tg: rozbor tg: názor tg: přehled tp: malware tp: AI

· Cisco Talos · Begun, the Patch Wars have

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.” The WLDR agent is a sophisticated PowerShell-based C2 memory implant that…

US

tg: varování tg: rozbor tp: malware tp: podvod

· Cisco Talos · UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

Elastic Security Labs is tracking an emerging threat named TELEPUZ, which we have discovered spreading widely via a CLICKFIX-VIDAR chain. This malware is in active development and has been operating since late April 2026, according to the infrastructure information we collected. The malware is full-featured, lightweight, and modular. While the number of C2 domains is currently small, the daily volume of builds uploaded to VirusTotal and the rapid pace of updates indicate active development and…

US

tg: varování tg: rozbor tp: malware tp: phishing

· Elastic Security · TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

3

AI Security Report 2026

For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that goes further. AI has crossed from assistant to operator. Where it once helped attackers prepare, it now runs the operation. Key observed findings AI has crossed from development aid to live attack operator. It now does…

veřejná správa IL

tg: rozbor tp: malware tp: phishing tp: AI tp: špionáž

· Check Point Research · AI Security Report 2026

2

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning…

finance telekomunikace US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Elastic Security · ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning…

finance telekomunikace US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Elastic Security · ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

1

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Note: SysAid was not compromised, and no SysAid vulnerability was involved. The attacker had already gained access to the victim environment and abused a legitimate software-deployment feature to deploy malware onto another machine within it. Key Points Check Point Research (CPR) tracks ‘Cavern Manticore’ as an Iran-nexus threat actor operating against Israeli targets, with a focus on the government and IT sectors. Cavern Manticore shares technical overlaps with other Iranian MOIS (Ministry of…

veřejná správa IL

tg: rozbor tp: malware tp: špionáž

· Check Point Research · Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

1

3

From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to release a DFIR Labs […] The post From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira appeared first on The DFIR Report.

US

tg: varování tg: rozbor tp: malware tp: ransomware

· The DFIR Report · From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

1

2

Millenium: A RAT Rewritten, A Threat Multiplied

Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone an architectural shift from .NET to native C++, while continuing to leverage the Telegram Bot API for command and control, requiring no dedicated server infrastructure. This blog also profiles the developer “ShinyEnigma”, and threat actor cluster “Y2K Operators” responsible for active Millenium RAT exploitation campaigns. Over 62,000 compromised endpoints across more than 160 countries have been identified,…

Telegram SG

tg: varování tg: rozbor tp: malware

· Group-IB · Millenium: A RAT Rewritten, A Threat Multiplied

1

1

1

Lost in relocation: analysis of a new loader distributing CASTLESTEALER

A previously undocumented Windows loader tracked as OXLOADER is delivering the CASTLESTEALER infostealer via malicious Google Ads, with low detection rates across static engines and sandbox detonations. The loader uses several obfuscation layers (control-flow flattening, opaque predicates, mixed Boolean-Arithmetic), self-modifying decryption stubs, and abuses the Windows .reloc section to stage shellcode. Elastic Security Labs identified OXLOADER in an active campaign targeting one of our…

Microsoft Google US

tg: varování tg: rozbor tp: malware

· Elastic Security · Lost in relocation: analysis of a new loader distributing CASTLESTEALER

1

1

1

1

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time.

JP

tg: rozbor tp: malware

· Trend Micro · Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

1

PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT

Elastic Security Labs's prior coverage of REF6598 documented an intrusion set whose Windows toolchain landed via Obsidian plugin abuse, escalated via an in-memory PE loader (PHANTOMPULL), and finished with a RAT (PHANTOMPULSE). That post focused on delivery. This post analyzes the final stage: PHANTOMPULSE, an implant that ships three process-injection techniques, resolves its C2 through Ethereum/Base/Optimism transaction inputs, and bypasses UAC via the public schuac technique. The analysis…

US

tg: rozbor tp: malware tp: AI

· Elastic Security · PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT

1

1

1

1

Supply Chain Attack: rilevata nuova ondata di compromissione pacchetti NPM

Rilevata una campagna su larga scala di compromissione della supply chain nell'ecosistema npm, denominata "Mini Shai-Hulud". L'attacco sfrutta un malware di tipo worm per infiltrarsi negli ambienti di sviluppo e nelle pipeline di Continuous Integration/Continuous Deployment (CI/CD). L'obiettivo primario è l'esfiltrazione di credenziali sensibili e la successiva propagazione automatizzata attraverso la pubblicazione di versioni malevole di pacchetti legittimi.

npm IT

tg: varování tp: malware tp: dodavatelský řetězec tp: identita

· CSIRT Itálie (ACN) · Supply Chain Attack: rilevata nuova ondata di compromissione pacchetti NPM

1

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.

KEV ✓ · ransomware EPSS 1.00 CVE-2025-55182 US

tg: varování tg: rozbor tp: malware tp: ransomware

· The DFIR Report · Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

2

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

Executive Summary SentinelLABS has identified PCPJack, a credential theft framework that worms across exposed cloud infrastructure and removes artifacts associated with TeamPCP, a threat actor persona who claimed several high-profile supply chain intrusions throughout early 2026. The toolset harvests credentials from cloud, container, developer, productivity, and financial services, then exfiltrates the data through attacker-controlled infrastructure while attempting to spread to additional…

Docker Kubernetes Redis MongoDB US

tg: varování tg: rozbor tp: malware tp: podvod tp: identita

· SentinelLabs · PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

Elastic Security Labs identified a new Brazilian banking trojan that we are tracking as TCLBANKER, a malware family we assess is a major update of the MAVERICK/SORVEPOTEL family. The campaign, tracked as REF3076, features a loader with robust anti-analysis capabilities that deploys two embedded .NET Reactor-protected modules: a full-featured banking trojan and a worm module for self-propagation. The banking trojan monitors the victim's browser address bar via UI Automation, targeting 59…

Logitech finance US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

1

1

Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities

TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, and potential supply-chain attacks.

JP

tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Trend Micro · Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities

1

1

1

1

Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT

A follow-up publication will provide a deeper technical analysis of PHANTOMPULSE itself, covering its injection engines, persistence internals, and C2 protocol in greater detail. Preamble Elastic Security Labs has identified a novel social engineering campaign that abuses the popular note-taking application, Obsidian, as an initial access vector. The campaign, which we track as REF6598, targets individuals in the financial and cryptocurrency sectors through elaborate social engineering on…

Obsidian Shell Commands Hider finance US

tg: varování tg: rozbor tp: malware tp: phishing

· Elastic Security · Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT

1

2

How we caught the Axios supply chain attack

Preamble Last Monday night I was working late and a Slack alert came in from a monitoring tool I had built three days earlier. Axios compromised; one of the most popular npm packages in the world. My heart started racing, I knew every second mattered to respond and limit the damage. But honestly it was so crazy that I thought it must be a false positive. I checked and rechecked everything a few times even though it seemed very obviously malicious. It wasn't a false positive. It was one of the…

axios US

tg: incident tg: rozbor tp: malware tp: dodavatelský řetězec tp: AI

· Elastic Security · How we caught the Axios supply chain attack

Hooked on Linux: Rootkit Detection Engineering

Introduction In part one, we examined how Linux rootkits work: their evolution, taxonomy, and techniques for manipulating user space and kernel space. In this second part, we turn to detection engineering. We begin by showing why static detection is often unreliable against Linux rootkits, even when binaries are only trivially modified, and then move on to behavioral and runtime signals that defenders can use instead. From shared object abuse and LKM loading to eBPF, io_uring, persistence, and…

Linux US

tg: rozbor tg: návod tp: malware

· Elastic Security · Hooked on Linux: Rootkit Detection Engineering

2

Inside the Axios supply chain compromise - one RAT to rule them all

Elastic Security Labs released initial triage and detection rules for the Axios supply-chain compromise. This is a detailed analysis of the RAT and payloads. Introduction Elastic Security Labs identified a supply chain compromise of the axios npm package, one of the most depended-upon packages in the JavaScript ecosystem with approximately 100 million weekly downloads. The attacker compromised a maintainer account and published backdoored versions that delivered a cross-platform Remote Access…

axios plain-crypto-js US

tg: incident tg: rozbor tp: malware tp: dodavatelský řetězec

· Elastic Security · Inside the Axios supply chain compromise - one RAT to rule them all

Elastic releases detections for the Axios supply chain compromise

Elastic Security Labs is releasing an initial triage and detection rules for the Axios supply-chain compromise. We have released a detailed analysis on the Axios compromise RAT and payloads. Elastic Security Labs filed a GitHub Security Advisory to the axios repository on March 31, 2026 at 01:50 AM UTC to coordinate disclosure and ensure the maintainers and npm registry could act on the compromised versions. Introduction We are currently tracking a supply chain attack involving malicious Axios…

axios US

tg: zranitelnost tg: rozbor tp: malware tp: dodavatelský řetězec

· Elastic Security · Elastic releases detections for the Axios supply chain compromise

1