The uploader_client.exe command-line utility allows for rapid and granular data theft.
Laura French
A self-propagating script was added to @automagik/genie and @pgserve packages.
Attackers could have extracted a GITHUB_TOKEN secret, potentially enabling unauthorized changes.
The median lead time between activity surge and advisory publication was 11 days.
The stealthy CGrabber malware targets a wide array of apps, browsers and extensions.
Researchers warn malicious bots may spoof trusted user agents to disguise their intent.
Attackers on the same network can alter nginx configurations, leading to complete takeover.
Suspected former Black Basta affiliates impersonate help desks to deploy RMM software.
The company is revoking and rotating certificates “out of an abundance of caution.”
AI extensions are also more likely to have cookie, scripting and tabs permissions.