PrivacySignal
Breach

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Microsoft Threat Intelligence · · International · Data Breaches

A self-propagating worm embedded in over 400 malicious npm packages spread through software supply chains by automatically republishing infected updates, stealing credentials along the way. Microsoft's security team has published a detailed breakdown of how the attack worked and how to detect or remediate it.

Why this matters: Most developers do not inspect every package they pull in. That is the whole point of this attack. A worm that spreads by republishing itself inside a trusted ecosystem does not need to trick you once — it keeps moving on its own. Four hundred compromised packages is not a small incident. Any project that pulled in an affected dependency may have handed over credentials without knowing it. If your team uses npm, now is the time to check, not later.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
BleepingComputer · · International

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
CyberScoop · · US Federal

Massive supply-chain attack compromises 440 packages under four hours

Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages. The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
Schneier on Security · · International

Iran Cyberattacks Against Minnesota Water Systems

Attribution is preliminary, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself. “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”...

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
Microsoft Threat Intelligence · · International

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →