Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: promised Clear Filter

Self-propagating supply chain attack hits 187 npm packages

Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack, with a malicious self-propagating payload to infect other packages. The coordinated worm-style campaign dubbed 'Shai-Hulud' started yesterday with the compromise of the @ctrl/tinycolor npm package, which receives over 2 million weekly downloads. Since then, the campaign has expanded significantly and now includes packages published under CrowdStrike's npm namespace. From tinycolor to

The Promised LAN

πŸ–§ The Promised LAN The Promised LAN is a closed, membership only network of friends that operate a 24/7 always-on LAN party, running since 2021. The vast majority of documentation is maintained on the LAN, but this website serves to give interested folks, prospective members or friends an idea of what the Promised LAN is, and how it works. A Manifesto for The Promised LAN For background on why we started the lan, what we hope to achieve, and how we approach the social-technical dynamics, we h

US nuclear weapons agency reportedly hacked in SharePoint attacks

Unknown threat actors have reportedly breached the National Nuclear Security Administration's network in attacks exploiting a recently patched Microsoft SharePoint zero-day vulnerability chain. NNSA is a semi-autonomous U.S. government agency part of the Energy Department that maintains the country's nuclear weapons stockpile and is also tasked with responding to nuclear and radiological emergencies within the United States and abroad. A Department of Energy spokesperson confirmed in a stateme

NPM package β€˜is’ with 2.8M weekly downloads infected devs with malware

The popular NPM package 'is' has been compromised in a supply chain attack that injected backdoor malware, giving attackers full access to compromised devices. This occurred after maintainer accounts were hijacked via phishing, followed by unauthorized owner changes that went unnoticed for several hours, potentially compromising many developers who downloaded the new releases. The 'is' package is a lightweight JavaScript utility library that provides a wide variety of type checking and value v

Keylogger campaign hitting Outlook Web Access on vulnerable Exchange servers goes global

Serving tech enthusiasts for over 25 years.TechSpot means tech analysis and advice you can trust Facepalm: Keylogging malware is a particularly dangerous threat, as it is typically designed to capture login credentials or other sensitive data from users. When you add a compromised Exchange server to the mix, it creates an even nastier situation for any organization. Researchers from Positive Technologies recently unveiled a new study on a keylogger-based campaign targeting organizations worldw

Keylogger campaign hitting Microsoft Exchange servers goes global

Serving tech enthusiasts for over 25 years.TechSpot means tech analysis and advice you can trust Facepalm: Keylogging malware is a particularly dangerous threat, as it is typically designed to capture login credentials or other sensitive data from users. When you add a compromised Exchange server to the mix, it creates an even nastier situation for any organization. Researchers from Positive Technologies recently unveiled a new study on a keylogger-based campaign targeting organizations worldw

Scania confirms insurance claim data breach in extortion attempt

Automotive giant Scania confirmed it suffered a cybersecurity incident where threat actors used compromised credentials to breach its Financial Services systems and steal insurance claim documents. Scania told BleepingComputer that the attackers emailed several Scania employees, threatening to leak the data online unless their demands were met. Scania is a major Swedish manufacturer of heavy trucks, buses, and industrial and marine engines and is a member of the Volkswagen Group. The company,

Double-A shooter MindsEye goes from promising GTA killer to triple-A dumpster fire seconds after launch

In context: Developer Build A Rocket Boy and publisher IO Interactive positioned their genre-bending sci-fi shooter MindsEye as the next big blockbuster of 2025. Instead, it's breaking blocks in ways no one expected. Mission-breaking bugs and crippling glitches made the game nearly unplayable. MindsEye launched Tuesday with high hopes – and fell apart within seconds. The brainchild of former Grand Theft Auto producer Leslie Benzies, the third-person action-adventure follows Jacob Diaz, a soldie