Entry Thumbnail

Strengthening supply chain security: Preparing for the next malware campaign

The open source ecosystem continues to face organized, adaptive supply chain threats that spread through compromised credentials and malicious package lifecycle scripts. The most recent example is the multi-wave Shai-Hulud campaign. While individual incidents differ in their mechanics and speed, the pattern is consistent: Adversaries learn quickly, target maintainer workflows, […]

Posted by
Entry Thumbnail

Palo Alto Vulnerability Report

/ **security-research** Public # Palo Alto Vulnerability Report ## Package No package listed ## Affected versions TBD ## Patched versions TBD ## Description ### Impact Vendor Palo Alto Networks ### Affected Product PA-54xx All supported versions of PAN-OS. Tested: PAN-OS 10.x – 10.2.16-h1 PAN-OS 11x – 11.2.1 ### Important Dates […]

Posted by
Entry Thumbnail

GachiLoader: Defeating Node.js Malware with API Tracing

Research by: **Sven Rath** ( **@eversinc33**), Jaromír Hořejší ( **@JaromirHorejsi**) ## Key Points – The YouTube Ghost Network is a malware distribution network that uses compromised accounts to promote malicious videos and spread malware, such as infostealers. – One of the observed campaigns uses a new, heavily obfuscated loader malware written in Node.js, which we […]

Posted by