mitre-ta0043
152 articles with this tag
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
MEDIUM
CRITICAL
HIGH
CRITICAL
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
MEDIUM
HIGH
LOW
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
MEDIUM
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Detect and disrupt AI-themed attacks with Microsoft Defender
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
Shai-Hulud npm worm resurfaces, bypassing security scans
ASCII smuggling crosses over from AI prompt injection to phishing evasion
VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
Trezor Supply Chain Breach Now Impacts 81,000 Customers
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
Two alleged TeamPCP hackers arrested over global supply chain attacks
A Student Said He Was a Hobby Plane Spotter. He Was Allegedly Taking Photos for the Chinese Government
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure
How QR-code phishing can slip past corporate security measures
A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
153GB of stolen credentials surface after LiteLLM supply chain attack
Valve warns Steam hardware buyers: Expect fake delivery scams
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Massive supply-chain attack compromises 440 packages under four hours
How legitimate cloud platforms enable phishers to bypass MFA
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Arch Linux temporarily disables AUR package adoption amid malicious takeover surge
AI is 'both the weapon and the target' in latest wave of cyberattacks
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Amazon attributes axios, debug, chalk NPM attacks to DPRK’s Sapphire Sleet
AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos
FBI warns of scammers impersonating agency online
NPM ecosystem hit with two new supply chain compromises
Warning: Scammers are using FaceTime to empty bank accounts
Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Celebrating Canada Day with Localized Managed Phishing
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
GitHub’s public APIs are becoming an enterprise reconnaissance tool
North Korean Hackers Target Open Source Developers in Supply Chain Attacks
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
TanStack npm compromise: 42 packages published with valid SLSA provenance via OIDC token theft from runner memory
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage
GTA 6 Scams Emerge as Pre-Orders Open
4 ways to protect the company against vishing attacks
Microsoft Attributes Mastra AI Supply Chain Attack to North Korea
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
Fake Boots emails target millions in large phishing campaign
Mastra npm packages compromised in 'easy-day-js' supply chain attack
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
FBI shuts down 13 ‘consulting’ websites used for suspected Chinese espionage
Interpol Dismantles SniperDz Phishing-as-a-Service Platform
China-linked recon botnet outpaces enterprise defenses
FBI seizes 13 websites linked to alleged Chinese intelligence-gathering effort
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Tempo news website hit by massive DDoS cyberattack
⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5
New IronWorm malware hits 36 packages in npm supply-chain attack
Why supply chain attacks work and what detection can actually do about it
Red Hat npm packages compromised to steal developer credentials
Dozens of Red Hat packages backdoored through its offical NPM channel
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
Russia-linked threat group put ChatGPT to work from lure to payload
What scanners are actually trying against AI infrastructure
CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain
Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign
Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested
GitHub internal repositories breached
GitHub links repo breach to TanStack npm supply-chain attack
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
The IBM X-Force Index 2026 explains all three in one finding.
GitHub Confirms Hack Impacting 3,800 Internal Repositories
AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks
Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool
FIFA World Cup scams target fans and businesses
201 arrested in INTERPOL disruption of phishing and fraud networks
TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code
Hunting the Behavior Behind npm Supply Chain Attacks
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
Small Defense Firms Lack Network Data to Stop Nation-State Hackers, Analyst Says
Social Engineering Leveled Up. Has Your Security Program?
Ubuntu infrastructure has been down for more than a day
PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials
'Mini Shai-Hulud' supply chain attack targets SAP npm packages
Kuse Web App Abused to Host Phishing Document
More fake extensions linked to GlassWorm found in Open VSX code marketplace
Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers
Tradecraft Tuesday Recap: axios npm Supply Chain Compromise
Supply chain attacks hit Checkmarx and Bitwarden developer tools
A dozen allied agencies say China is building covert hacker networks out of everyday routers
Anthropic probes alleged third-party breach of Claude Mythos