Security researchers report North Korea-linked actors have uploaded 197 new malicious npm packages to distribute an updated OtterCookie malware variant. Active since November 2023, the Contagious Interview campaign targets developers via software supply chain abuse, increasing the risk of downstream compromises. Teams should audit npm dependencies, block typosquats, and monitor developer endpoints for package abuse.
Source: Security Affairs
‘HashJack’ Exploit Abuses URL Fragments to Steer AI Browsers; Microsoft and Perplexity Patched, Gemini Still at Risk
Cato Networks disclosed an AI browsing vulnerability dubbed HashJack that hides malicious commands in the “#” fragment of URLs, enabling client-side manipulation that servers don’t see. Microsoft and Perplexity have issued fixes, but Google’s Gemini remains exposed, underscoring the need for strict URL sanitization and guardrails in AI-powered browsing features.
Source: HackRead
CISA Adds Actively Exploited OpenPLC ScadaBR XSS (CVE-2021-26829) to KEV
The U.S. CISA added a cross-site scripting flaw in OpenPLC ScadaBR to its Known Exploited Vulnerabilities catalog, citing active exploitation. The XSS impacts both Windows and Linux deployments; OT operators should prioritize remediation, restrict console access, and monitor logs for suspicious operator session activity.
Source: TheHackerNews
Microsoft Confirms Windows Password Failures—No Fix Yet
Microsoft has acknowledged a Windows issue that is causing password authentication failures, with no immediate fix available. Enterprises should review recent updates, implement available mitigations, and follow Microsoft advisories while monitoring for authentication anomalies across endpoints and domain services.
Source: Forbes Security
Google Pulls Spyware from Play Store—Users Urged to Delete Flagged Apps
Google’s latest Play Store action targets spyware apps, with users advised to remove implicated titles immediately. Security teams should push device checks, review app permissions, and enforce mobile application management policies to prevent reinstallation and detect surveillance-style behaviors.
Source: Forbes Security
Play Ransomware Cartel Claims ADC Aerospace Breach—Proof Not Yet Provided
The Play group has listed ADC Aerospace on dark web leak sites, alleging a breach that could impact a U.S. defense contractor’s data. While unverified, the claim highlights ongoing extortion tactics against the defense supply chain; organizations should prepare for data-leak pressure even before technical evidence surfaces.
Source: CyberNews
Israel’s IDF Bans Android Phones, Makes iPhones Mandatory to Thwart Hacks
In a high-stakes policy shift, the Israel Defense Forces reportedly banned Android devices, standardizing on iPhones to reduce smartphone attack exposure. The move spotlights operational security trade-offs and may influence enterprise device strategies, including stricter platforms and unified MDM hardening.
Source: Forbes Security
You May Also Be Interested In...
FBI Warns All Smartphone Users—Stop Answering These Calls
Apple Update Warning For All iPhone 17, 16 And 15 Users—Act Now
Amazon Customers Issued 48 Hour Warning—Attacks Have Started