Today > 5 Critical | 6 High | 28 Medium vulnerabilities - You can now download lists of IOCs here!
3 attack reports | 387 vulnerabilities
ReversingLabs researchers discovered malicious versions of the popular npm package @lottiefiles/lottie-player. Versions 2.0.5, 2.0.6, and 2.0.7 were compromised and used to spread malicious code designed to steal crypto wallet assets. The attackers altered the lottie-player.js file, replacing its c…
ESET researchers have discovered previously unknown Linux backdoors attributed to the China-aligned Gelsemium APT group. The main backdoor, named WolfsBane, is the Linux equivalent of Gelsemium's Gelsevirine backdoor for Windows. Another backdoor, FireWood, is connected to the group's Project Wood …
Federal authorities have shut down PopeyeTools, an illicit online marketplace operating since 2016, which sold stolen credit card data and cybercrime tools. Three alleged administrators from Pakistan and Afghanistan face criminal charges. The platform offered credit card numbers, bank account infor…