Entry Thumbnail

Our plan for a more secure npm supply chain

Addressing a surge in package registry attacks, GitHub is strengthening npm’s security with stricter authentication, granular tokens, and enhanced trusted publishing to restore trust in the open source ecosystem. Open source software is the bedrock of the modern software industry. Its collaborative nature and vast ecosystem empower developers worldwide, driving […]

Posted by
Entry Thumbnail

Nimbus Manticore Deploys New Malware Targeting Europe

Since early 2025, Check Point Research (CPR) has tracked waves of Nimbus Manticore activity. Known as **UNC1549 or Smoke** **Sandstorm,** Nimbus Manticore is a mature Iran-nexus APT group that primarily targets aerospace and defense organizations in the Middle East and Europe. Some of its operations were also previously described as the _Iranian DreamJob_ campaign. […]

Posted by
Entry Thumbnail

Entrust nShield Connect XC – Multiple Vulnerabilities Leading to Insecure Boot Chain Protections

**security-research** Public # Entrust nShield Connect XC – Multiple Vulnerabilities Leading to Insecure Boot Chain Protections ## Package ## Affected versions ## Patched versions ## Description ### Summary The tested nShield Connect XC HSM appliance (software version 13.6.3) can be rooted and backdoored via physical attack vectors in less than […]

Posted by
Entry Thumbnail

Under the Pure Curtain: From RAT to Builder to Coder

**Research by:** Antonis Terefos ( **@Tera0017**) The **Pure malware family** is a suite of malicious tools developed and sold by the author known as **PureCoder**. This suite includes **PureHVNC RAT** (a remote administration tool and predecessor to **PureRAT**), **PureCrypter** (a malware obfuscator), **PureLogs** (a stealer/logger), and several other tools. The malicious software is advertised and distributed through underground forums, Telegram channels, […]

Posted by