Supply-chain attack on VaultBridge SDK exposes 1.2M enterprise tokens
A poisoned npm release of @vaultbridge/sdk silently exfiltrated CI/CD secrets for nine days before maintainers noticed. We pieced together the timeline.
We bought five. Three actually work. Here is what is in the box, and which mail providers still wave them through.
Boot-level implants found on three vendors switches share a loader that survives factory reset.
A signed driver could be coerced into arbitrary memory writes from user-mode. Patch out, IOC list below.
A two-year operation across nine jurisdictions ends with 31 arrests and a leaked playbook detailing carrier-insider recruitment.
Forks of the open-source Ferrum AI model marketplace are being seeded with backdoors that activate only at inference time.
A debug fallback path remained reachable in production builds. The bank says no funds were moved; researchers say that is not the question to ask.
Original reporting, advisories, and IOCs in your inbox by 06:00 UTC.
SubscribeFree. Unsubscribe in one click.