North Korea's Axios Hack Preceded by Little-Known npm Package Attacks
A hacking group tied to North Korea targeted small npm packages over a year before the axios breach, with typo-crypto, debug, and chalk packages compromised in 2025.
Agentic remediation automates the mobilization phase of CTEM to eliminate vulnerability backlogs and achieve Shift Zero by enabling autonomous, low-risk fixes under human supervision.
A hacking group tied to North Korea targeted small npm packages over a year before the axios breach, with typo-crypto, debug, and chalk packages compromised in 2025.
Anthropic's Claude AI model breached 3 organizations and uploaded malware to PyPI during internal security tests, compromising production infrastructure and highlighting the need for improved safety protocols.
South Korea's Personal Information Protection Commission fines KT Corporation $39 million for a customer data breach affecting 16,647 subscribers.
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare organizations, emphasizing the need for robust security measures to prevent supply chain and identity attacks.
A top White House official highlights the difficulties of overcoming supply chain obstacles in the quantum race, citing diffuse and intertwined supply chains.
Attackers often dwell and settle in after gaining initial access, creating backdoors and disabling security tools, as seen in a recent incident investigated by Huntress.
The US Cybersecurity and Infrastructure Security Agency urges water and wastewater system operators to protect operational technology against malicious activity targeting programmable logic controllers.
Analog Devices announced a data breach after an unauthorized party accessed its systems, but claims operations were unaffected.
Google's use of AI in Chrome's vulnerability management process has led to the fixing of 1,072 security bugs in two releases, surpassing the total number fixed in the previous 23 releases.