At least 18 widely used JavaScript packages — including chalk, debug, and ansi-styles — were briefly trojanized after a maintainer was phished, affecting libraries with roughly two billion weekly downloads. The payload focused on stealing cryptocurrency, but experts warn similarly seeded packages could exfiltrate secrets or enable broader malware outbreaks. Teams should lock dependencies, audit packages updated on Sept 8–9, and rotate any secrets exposed to affected build environments.
Source: KrebsOnSecurity
Salesloft/Drift breach traced to months-long GitHub compromise; OAuth tokens abused for Salesforce data theft
Salesloft confirmed attackers accessed its GitHub in March, later stealing OAuth credentials used by Drift integrations to siphon customer Salesforce data. The victim list continues to grow and now includes security vendors, underscoring the systemic risk of third‑party OAuth and SaaS-to-SaaS integrations. Organizations should review Drift/Salesforce app consent, revoke/rotate tokens, and monitor anomalous API activity.
Source: SecurityWeek
Malvertising pushes fake GitHub Desktop installers to EU IT workers
Researchers uncovered a long-running malvertising campaign using search ads and convincingly cloned sites to deliver trojanized GitHub Desktop installers, aiming for initial access, credential theft, and potential ransomware deployment. The operation avoids raising alarms by mimicking legitimate flows; defenders should block ad click-through for software downloads, enforce code-signing checks, and allowlist vendor domains.
Source: Help Net Security
CISA flags TP-Link routers under active attack — patch now
The US government warned that two TP-Link router flaws are being actively exploited in the wild, with reporting of a third bug also under attack. Home and small-office gear remains a favored foothold for botnets and intrusion campaigns; admins should patch immediately, disable remote administration, and segment or replace unmanaged edge devices.
Source: The Register
Signal introduces end-to-end encrypted chat backups
Signal is rolling out an opt-in secure backup feature designed to preserve chat history without exposing content to cloud providers or Signal itself. The move addresses long-standing usability pain points while maintaining strong privacy guarantees, though users should store recovery keys safely to avoid irreversible data loss.
Source: Help Net Security
Nearly 500 researchers urge EU to rethink CSAM scanning proposal
An open letter signed by hundreds of cryptographers and security researchers warns that the EU’s latest “Chat Control” child-safety proposal would weaken digital security and privacy without delivering effective protections. The group argues client-side scanning and similar measures create systemic risks by undermining end-to-end encryption and device security.
Source: Help Net Security
Mitsubishi Electric to acquire Nozomi Networks for nearly $1B, reshaping OT security landscape
The industrial giant will make Nozomi a wholly owned subsidiary, consolidating visibility and threat detection capabilities for critical infrastructure customers. The deal signals continued convergence between operations technology and IT security and could accelerate platform integration across industrial ecosystems.
Source: SecurityWeek
You May Also Be Interested In...
Plex urges password resets following data breachGPUGate: Google ads and fake GitHub commits used to target IT firms
MostereRAT uses AnyDesk/TightVNC for covert full access