• On November 7th, security researchers discovered a dangerous malicious npm package called “@acitons/artifact” that had already been downloaded more than 206,000 times.

    The package was designed to look like the legitimate “@actions/artifact” package used by developers building tools with GitHub Actions.

    This was a classic typosquatting attack where the attackers swapped the letters to make the name appear correct at first glance.

    The malware’s goal was clear and focused. When this package was installed during a build process in GitHub-owned repositories, it would steal authentication tokens available in the build environment.

    With these tokens, attackers could then publish new malicious code directly from GitHub’s own account, creating a serious threat to the entire platform’s security.

    The attack worked through a hidden installation script embedded in the package. Specifically, six versions of the malicious package included a post-install hook that automatically downloaded and ran hidden malware code.

    Veracode security analysts identified that this malware was not detected by common antivirus software when first discovered, making it especially dangerous to organizations relying on those protection tools.

    This campaign highlights a critical vulnerability in the software supply chain, which is why it ranked as the third most important security concern in the OWASP Top 10 2025 list.

    The attack targeted GitHub’s continuous integration and continuous deployment platform, showing how criminals are increasingly focusing on the tools that developers trust every day.

    Veracode security researchers noted that the malware used clever techniques to hide its true behavior and avoid automatic detection.

    Malicious code

    The malicious code was obfuscated and compiled using special tools that convert shell scripts into binary files, making it harder to analyze.

    The package contained a specific mechanism to stop working after a certain date, with each version set to expire within days of release.

    This time-based trigger suggests the attackers were testing different versions of their code while staying hidden from security systems.

    The infection mechanism worked in stages. When installed, the malware executed as a bash script that reset its own environment variables to change how it ran.

    This triggered the loading of an obfuscated file called “verify.js” hidden inside a Node package. The verify.js file contained checks for specific GitHub environment variables that only exist when code runs inside GitHub Actions.

    The code specifically targeted only repositories owned by the GitHub organization itself, confirming this was a precision attack.

    The malware obtained an encryption key from an external server, encrypted the stolen tokens, and then sent this encrypted data to a command and control server.

    Developers using Veracode’s Package Firewall were protected from this threat immediately after the discovery, but the incident demonstrates how vulnerable package managers remain to these sophisticated supply chain attacks.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. military’s war on drugs in Latin America has a (borrowed) name. “Today, I’m announcing Operation SOUTHERN SPEAR,” Defense Secretary Pete Hegseth posted Thursday. “Led by Joint Task Force Southern Spear and SOUTHCOM, this mission defends our Homeland, removes narco-terrorists from our Hemisphere, and secures our Homeland from the drugs that are killing our people. The Western Hemisphere is America’s neighborhood—and we will protect it.”

    Hegseth made the announcement on social media; he hasn’t held a press conference since late June

    And the Pentagon’s 20th known boat strike killed four more people on Wednesday, raising the death toll in these U.S. attacks to at least 80 people, CBS News reported. 

    ICYMI: To date, “U.S. officials have not provided specific evidence that the vessels were smuggling drugs or posed a threat to the United States” on any of the 20 known strikes, CBS reminds readers. And U.N. human rights chief Volker Türk said this week there are “strong indications” of “extrajudicial killings” in the Pentagon’s boat attacks. 

    “From what we know, these instances violate international human rights law,” he told French media.

    Notable: It wasn’t immediately clear how Hegseth’s announcement relates to the pre-existing Operation Southern Spear, an effort to “operationalize” the use of aerial and seaborne drones that the Navy’s 4th Fleet began running in the region in January. 

    A widening window into the White House’s legal decision-making process is emerging after more reporting Thursday from Charlie Savage of the New York Times, who has been tracking the development of a secret memo from the Justice Department’s Office of Legal Counsel. 

    The memo declared “extrajudicial killings of people suspected of running drugs were lawful as a matter of Mr. Trump’s wartime powers,” which Savage reports “contradicts a broad range of critics, who have rejected the idea that there is any armed conflict and have accused Mr. Trump of illegally ordering the military to commit murders.”

    The conclusion of the memo also “offers potential legal defenses if a prosecutor were to charge administration officials or troops for involvement in the killings. Everyone in the chain of command who follows orders that comply with the laws of war has battlefield immunity, the memo says, because it is an armed conflict,” the Times reports. 

    Expert reax: “It would be difficult to establish that the cargo on these vessels was a military objective under the law of war because there is no obvious connection between a shipment of drugs and military action by these supposed groups,” said former State Department lawyer Brian Finucane. 

    Another seemingly confusing wrinkle: “Despite concluding that an armed conflict is underway, the memo also says the operation is not covered by the War Powers Resolution,” Savage writes. Continue reading (gift link), here

    New: Just 29% of Americans support the U.S. military killing drug suspects without the involvement of a court or judge, according to survey results from Reuters/Ipsos published Friday. 

    More than half openly opposed the killings (51%), including 27% of Republicans polled in a survey of 1,200 adults that concluded this week. 

    Less than half supported designating drug cartels as foreign terrorist organizations (47%), including 75% of Republicans compared to just 22% of Democrats surveyed. 

    And starting a war to depose Venezuela’s leader? Just 21% of Americans supported it versus 47% opposed—including 49% of voters who said they are not aligned with the GOP or Democrats. Read the rest, here

    Additional reading:Family of Fisherman Killed in U.S. Military Strike Says It Wants Justice,” the New York Times reported Thursday from Colombia. 


    Welcome to this Friday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson and Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1969, NASA launched Apollo 12, its second moon-landing mission. 

    Industry

    Boeing Defense workers have approved a new contract, ending a strike that idled fighter-jet and weapons production in St. Louis for three months. “The roughly 3,200 members of the International Association of Machinists and Aerospace Workers (IAM) District 837 voted 68% in favor of approving the five-year contract. They will start returning to work as early as Sunday,” Reuters reported on Thursday. The New York Times also has a report, here.

    Anduril says it will build an autonomous vessel prototype in Korea. It’ll be the first fruit of a partnership with shipbuilding tidal HD Hyundai Heavy Industries, and is intended to lead to subsequent vessels built at the former Foss Shipyard in Seattle, Wash., the company said. The goal is to have infrastructure in place to compete for the Navy’s Modular Attack Surface Craft, or MASC, program, a combination of the service’s previous large and medium unmanned surface vessel programs. Defense One’s Lauren C. Williams reports, here.

    Related: See “How American and Chinese Drone Arsenals Stack Up,” via the Wall Street Journal reporting Friday. 

    Blue Origin’s giant reusable rocket matches SpaceX’s landing on second flight. Ten months after missing its “stretch goal” of sticking the landing in its maiden flight, the heavylift New Glenn booster touched down safely on a landing ship Thursday after launching a probe toward Mars. “I think New Glenn is the most promising competitor for SpaceX right now because it is the only other medium/heavy-lift launcher with reusability. ULA’s Vulcan and Arianespace’s Ariane 6 missed the boat on reusability and have no real chance at being cost-competitive,” said Todd Harrison, a senior fellow at the American Enterprise Institute, told Defense One in January. Space-dot-com has more, here.

    Fresh possible U.S. arms sales include the first batch of assistance to Taiwan since Trump took office in January. That pending sale includes “spare and repair parts, consumables and accessories, and repair and return support for F-16, C-130, and Indigenous Defense Fighter aircraft” for about $330 million, the Pentagon’s Defense Security Cooperation Agency announced Thursday.  

    And in a smaller package intended for Iraq, the U.S. is on the verge of selling Baghdad an array of communications equipment for a “country-wide repeater system” totalling about $100 million. DSCA has details. Congress could object to either of these packages, though that prospect seems unlikely. 

    It’s now been a week since SecDef Hegseth announced his arms procurement makeover from the National War College at Fort McNair in Washington. “Move faster and invest more—or we just might make you,” was how Defense One’s Lauren C. Williams characterized his effort.

    Second opinion: “There's nothing remotely transformative about this strategy. The admin is simply fulfilling arms industry demands for bigger, longer contracts, reduced weapons testing, and the ability to determine contract prices. Of course, they're justifying it all by fearmongering on China,” says Julia Gledhill of the Washington-based Stimson Center think tank, writing Thursday on social media. “The result will be unfettered weapons development and production—regardless of need, cost, or reliability. Hard to imagine how military contractors could tighten their grip on USA, Inc… but here we are,” she added. 

    Additional reading: 

    Trump 2.0

    Developing: Trump’s State Department says four left-wing groups in Europe are anti-fascist “foreign terrorist organizations.” The groups span Germany, Italy and Greece, and State Secretary Marco Rubio said Thursday he plans to announce the terrorist designations sometime next week. 

    Rubio: “Groups affiliated with this movement ascribe to revolutionary anarchist or Marxist ideologies, including anti-Americanism, ‘anti-capitalism,’ and anti-Christianity, using these to incite and justify violent assaults domestically and overseas,” he said in a statement Thursday. 

    The groups include Germany-based “Antifa Ost,” two organizations from Greece—Armed Proletarian Justice and Revolutionary Class Self-Defense—and one out of Italy the State Department refers to as the “Informal Anarchist Federation/International Revolutionary Front.” 

    By the way: Antifa Ost—Antifa east, in German—is “not a formal organization but a label used by German police, intelligence services, and media to describe a cluster of more militant anti-fascist activists in eastern Germany,” extremism researcher Amarnath Amarasingam noted on social media Thursday. 

    The designations come at least partly in response to physical attacks against neo-Nazis in Germany, including this 2023 Dresden court case involving beatings of far-right extremists using clubs and hammers. The other three groups have carried out select attacks over the past two years that have included explosive devices, but those did not result in injuries, Reuters reports

    Additional reading: 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have uncovered critical remote code execution vulnerabilities impacting major artificial intelligence (AI) inference engines, including those from Meta, Nvidia, Microsoft, and open-source PyTorch projects such as vLLM and SGLang. “These vulnerabilities all traced back to the same root cause: the overlooked unsafe use of ZeroMQ (ZMQ) and Python’s pickle deserialization,”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Iranian state-sponsored threat actor known as APT42 has been observed targeting individuals and organizations that are of interest to the Islamic Revolutionary Guard Corps (IRGC) as part of a new espionage-focused campaign. The activity, detected in early September 2025 and assessed to be ongoing, has been codenamed SpearSpecter by the Israel National Digital Agency (INDA). “The

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • NVIDIA has issued a critical security update addressing two high-severity vulnerabilities in its NeMo Framework that could allow attackers to execute malicious code and escalate privileges on affected systems.

    The vulnerabilities, tracked as CVE-2025-23361 and CVE-2025-33178, both carry a CVSS score of 7.8 and affect all versions of the NeMo Framework before version 2.5.0 across all platforms.

    NVIDIA NeMo Framework Vulnerabilities

    The first vulnerability, CVE-2025-23361, exists in a framework script, where malicious input from an attacker may cause improper control over code generation.

    The second flaw, CVE-2025-33178, resides in the Bert services component and enables code injection through malicious data.

    Both vulnerabilities share the same attack vector and require local access with low privileges.

    CVE IDDescriptionCVSS ScoreCWE
    CVE-2025-23361Improper control of code generation in framework script7.8CWE-94
    CVE-2025-33178Code injection in bert services component7.8CWE-94

    Successful exploitation could result in code execution, privilege escalation, information disclosure, and data manipulation, posing significant risks to organizations using the framework.

    The vulnerabilities were discovered and reported by security researchers from TencentAISec and NISL lab at Tsinghua University, highlighting the importance of collaborative security research.

    All versions of the NVIDIA NeMo Framework before 2.5.0 are vulnerable, regardless of operating system or platform. Organizations using earlier software branch releases are also at risk and should upgrade immediately.

    NVIDIA recommends that users clone or update to the NeMo Framework version 2.5.0 or later, available from the official NVIDIA GitHub repository and the PyPI package manager.

    The company emphasizes that users on earlier branch releases should upgrade to the latest branch version.

    Organizations should assess their specific configurations and apply the security update promptly to mitigate potential exploitation risks.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post NVIDIA NeMo Framework Vulnerabilities Allows Code Injection and Privilege Escalation appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The SmartApeSG campaign, also known as ZPHP or HANEY MANEY, continues to evolve its attack methods to compromise Windows systems with malicious remote access tools.

    First reported in June 2024, this campaign has shifted from using fake browser update pages to deploying sophisticated ClickFix-style techniques.

    The new approach tricks users into thinking they need to verify their identity through a fake CAPTCHA page, making the attack more deceptive and harder to detect.

    The campaign primarily targets users who visit compromised websites displaying hidden malicious scripts. When certain conditions are met, these scripts activate and present users with a fake “verify you are human” box.

    Injected SmartApeSG script in a page from the compromised site (Source - Internet Storm Center)
    Injected SmartApeSG script in a page from the compromised site (Source – Internet Storm Center)

    The attackers use this clever technique to bypass user suspicion and trick them into taking actions that lead to malware installation.

    Once activated, the fake CAPTCHA page initiates a chain of events designed to install NetSupport RAT on the victim’s computer.

    Fake CAPTCHA page displayed by the compromised site (Source - Internet Storm Center)
    Fake CAPTCHA page displayed by the compromised site (Source – Internet Storm Center)

    This remote access tool gives attackers complete control over infected machines, allowing them to steal data, monitor activity, and deploy additional malware.

    Internet Storm Center security analysts identified that the attack works by injecting malicious content directly into a user’s clipboard when they click the verification box.

    The injected content is a command string that uses the mshta command to retrieve and execute malicious code from attacker-controlled servers.

    Multi-stage approach

    This technique is particularly effective because it bypasses traditional security measures by relying on social engineering rather than software vulnerabilities.

    The persistence mechanism operates through a clever Windows trick. The malicious NetSupport RAT package maintains itself on infected computers by creating a Start Menu shortcut that runs a JavaScript file stored in the AppData\Local\Temp directory.

    This JavaScript file then launches the actual NetSupport RAT executable located in the C:\ProgramData\ directory. This multi-stage approach makes detection and removal more challenging for typical users.

    What makes SmartApeSG particularly dangerous is the constant evolution of its infrastructure. The domains, command and control servers, and malware packages change nearly daily, making threat intelligence updates critical for security teams.

    Organizations should educate users about clicking verification boxes on websites and implement network-level protections to block connections to known malicious domains associated with this campaign.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical security vulnerability has been identified in the Cisco Catalyst Center Virtual Appliance that could enable authenticated, remote attackers to escalate their privileges to Administrator on affected systems. This vulnerability CVE-2025-20341 caused by insufficient validation of user-supplied input, underscores the urgent need for patching among organizations that use the affected platform. The vulnerability resides […]

    The post Cisco Catalyst Center Vulnerability Allows Attackers to Escalate Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has disclosed critical security vulnerabilities affecting Cisco Unified Contact Center Express (Unified CCX) that could enable unauthenticated, remote attackers to execute arbitrary commands, escalate privileges to root, and bypass authentication mechanisms. The vulnerabilities reside in the Java Remote Method Invocation (RMI) process and CCX Editor application, presenting severe risks to enterprise contact center deployments. […]

    The post Multiple Cisco Unified CCX Vulnerabilities Enable Arbitrary Command Execution by Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Elastic Security Labs has uncovered a sophisticated campaign deploying a newly identified loader, dubbed RONINGLOADER, that weaponizes legitimately signed kernel drivers to systematically disable Microsoft Defender and evade endpoint detection and response (EDR) tools. Attributed to the Dragon Breath APT group (APT-Q-27), this campaign demonstrates a significant evolution in attack sophistication, primarily targeting Chinese-speaking users […]

    The post RONINGLOADER Uses Signed Drivers to Disable Microsoft Defender and Bypass EDR appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have uncovered a critical vulnerability in Cursor, the AI-powered code editor, that allows attackers to inject malicious code through rogue Model Context Protocol (MCP) servers. Unlike VS Code, Cursor lacks integrity checks on its runtime components, making it vulnerable to tampering through MCP server registration. The attack works by registering a local MCP […]

    The post Hackers Exploit Rogue MCP Server to Inject Malicious Code into Cursor’s Built-In Browser appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶