FakeGit Campaign Exploits 7,600 GitHub Repositories to Distribute SmartLoader Malware

FakeGit Campaign Exploits 7,600 GitHub Repositories to Distribute SmartLoader Malware

Cybersecurity experts have identified close to 7,600 harmful GitHub repositories, with over 800 masquerading as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to disseminate a malware variant known as SmartLoader, as part of an ongoing initiative referred to as FakeGit. According to Oleg Zaytsev, the lead security researcher at Island, in a…

Read More
JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware

JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware

The autonomous AI agent known as JadePuffer has been enhanced with a custom malware named EncForge, which is designed to encrypt AI-related assets, including training datasets, vector databases, and model checkpoints. Earlier this month, JadePuffer was identified as an agentic threat actor (ATA) capable of autonomously executing all phases of a ransomware attack, from gaining…

Read More
Exploitation of SonicWall SMA1000 Vulnerabilities as Zero-Days to Deploy Custom Malware

Exploitation of SonicWall SMA1000 Vulnerabilities as Zero-Days to Deploy Custom Malware

Recently, two vulnerabilities in the SonicWall SMA1000 were revealed to have been exploited in zero-day attacks for several weeks, enabling threat actors to install tailored malware on affected VPN devices. Last week, SonicWall issued a warning regarding the active exploitation of two previously unknown vulnerabilities in an exploit chain impacting SMA1000 Secure Mobile Access appliances….

Read More
We created a vulnerability vending machine: AI tokens in, zero-days out

We created a vulnerability vending machine: AI tokens in, zero-days out

Artificial intelligence is transforming the landscape of vulnerability research, yet much of the discussion remains theoretical, focusing on the potential capabilities of models rather than their current practical applications. Our goal was to address a more pragmatic inquiry: with the models we currently have access to, how effectively can AI assist in identifying genuine, exploitable…

Read More
AsyncAPI npm Packages Compromised by Credential-Stealing Malware

AsyncAPI npm Packages Compromised by Credential-Stealing Malware

Five harmful versions of AsyncAPI packages were uploaded to the Node Package Manager (npm) as part of a supply-chain attack that introduced a remote access trojan capable of stealing information. The attacker took advantage of a poorly configured GitHub Actions workflow, releasing trojanized packages within the @asyncapi namespace, which collectively garnered over 2.25 million downloads…

Read More
Back To Top