Attackers could have extracted a GITHUB_TOKEN secret, potentially enabling unauthorized changes.
Laura French
The median lead time between activity surge and advisory publication was 11 days.
The stealthy CGrabber malware targets a wide array of apps, browsers and extensions.
Researchers warn malicious bots may spoof trusted user agents to disguise their intent.
Attackers on the same network can alter nginx configurations, leading to complete takeover.
Suspected former Black Basta affiliates impersonate help desks to deploy RMM software.
The company is revoking and rotating certificates “out of an abundance of caution.”
AI extensions are also more likely to have cookie, scripting and tabs permissions.
The campaign targets open-source developers to steal credentials and deploy malware.
Anthropic launched “Project Glasswing” to restrict the availability of the new model to selected organizations.