Meta tags:
Headings (most frequently used words):
the, to, how, 2026, what, ai, cyber, threat, with, in, us, and, phishing, on, worm, its, security, earned, tools, why, detection, by, data, exposed, any, run, july, organizations, you, should, soc, backbox, news, want, free, photoshop, alternative, linux, get, affinity, today, ways, shai, hulud, npm, didn, fake, check, it, legitimate, one, provenance, target, was, developer, own, fix, costs, nothing, github, hardened, half, problem, boardroom, is, next, do, monday, morning, meta, ran, ads, that, contained, generated, child, sexual, abuse, imagery, psa, apple, private, relay, can, leak, your, real, ip, address, best, response, platforms, for, cyberattacks, water, systems, expand, 12, states, as, south, dakota, georgia, announce, incidents, veeam, terraform, mcp, django, patch, critical, flaws, led, cvss, 10, cross, tenant, bug, allowed, hackers, use, simple, claims, bypass, guardrails, black, hat, usa, summary, of, vendor, announcements, part, dutch, retailer, de, bijenkorf, warns, customer, may, be, after, incident, company, blogs, safeguarding, 200m, users, chongluadao, scales, validation, major, attacks, eu, hit, rats, stealers, this, month, tony, anscombe, edition, beyond, screenshot, verify, see, coverage, digest, new, ti, report, research, 750, rules, cfo, playbook, reduce, risk, without, scaling, team, tight, labor, market, building, resilience, against, aitm, leaders, know, kali365, targets, theft, via, device, code, hidden, infrastructure, reveals, hijacked, gov, websites, delivering, malware, forgotten, uefi, shims, undermining, secure, boot, hacking, exploit, db,
Text of the page (most frequently used words):
the (175), and (64), 2026 (56), that (37), backbox (25), org (24), for (23), news (22), admin (20), https (20), www (20), content (20), uploads (20), 2018 (20), website_backbox_text_black (20), png (20), with (19), npm (19), worm (18), more (17), #security (16), one (16), not (16), developer (15), august (14), you (13), keyv (13), package (13), what (12), this (11), from (11), read (11), was (11), july (10), general (10), patch (10), provenance (10), attack (9), chain (9), build (9), can (9), packages (9), crowdstrike (9), supply (9), any (8), how (8), their (8), most (8), its (8), they (8), hours (8), cloud (8), github (8), through (8), release (8), into (8), week (7), credentials (7), software (7), every (7), maintainer (7), account (7), poisoned (7), publishing (7), your (6), are (6), malware (6), data (6), threat (6), report (6), token (6), across (6), ran (6), tokens (6), time (6), compromise (6), link (5), services (5), run (5), code (5), cyber (5), after (5), latest (5), first (5), claims (5), found (5), veeam (5), have (5), published (5), legitimate (5), venturebeat (5), versions (5), jfrog (5), inside (5), meyers (5), credential (5), payload (5), half (5), identity (5), because (5), did (5), tooling (5), minutes (5), install (5), two (5), registries (5), attacker (5), malicious (5), will (4), tools (4), exposed (4), phishing (4), against (4), team (4), detection (4), users (4), incident (4), black (4), hat (4), part (4), hackers (4), simple (4), access (4), live (4), terraform (4), mcp (4), django (4), over (4), vulnerabilities (4), systems (4), states (4), least (4), response (4), real (4), generated (4), than (4), were (4), earned (4), stolen (4), ecosystem (4), now (4), automation (4), right (4), aikido (4), patching (4), public (4), publish (4), board (4), releases (4), own (4), pipeline (4), monthly (4), preinstall (4), attestation (4), trusted (4), editor (4), ways (4), want (4), told (4), going (4), but (4), who (4), itself (4), never (4), confirmed (4), registry (4), under (4), scroll (3), top (3), click (3), off (3), secure (3), infrastructure (3), organizations (3), should (3), why (3), hit (3), retailer (3), bijenkorf (3), announce (3), usa (3), summary (3), vendor (3), announcements (3), companies (3), bypass (3), guardrails (3), cybersecurity (3), flaws (3), cross (3), tenant (3), bug (3), service (3), cyberattacks (3), water (3), campaign (3), platforms (3), apple (3), private (3), relay (3), which (3), meta (3), ads (3), contained (3), abuse (3), shai (3), hulud (3), compromised (3), exposure (3), target (3), makes (3), exploitation (3), put (3), within (3), has (3), lived (3), keys (3), secrets (3), valid (3), control (3), point (3), require (3), script (3), reached (3), installs (3), default (3), before (3), dependency (3), extensions (3), names (3), directly (3), hooks (3), actions (3), five (3), each (3), get (3), open (3), dependencies (3), only (3), other (3), reach (3), said (3), had (3), here (3), where (3), still (3), then (3), version (3), vulnerability (3), something (3), free (3), those (3), would (3), down (3), developers (3), wiz (3), named (3), tied (3), linux (3), search (3), facebook (2), testing (2), contact (2), further (2), well (2), initial (2), rss (2), aggregator (2), feeds (2), exploit (2), limit (2), pagination (2), hijacked (2), targets (2), resilience (2), soc (2), risk (2), without (2), coverage (2), new (2), beyond (2), edition (2), attacks (2), company (2), dutch (2), warns (2), customer (2), may (2), record (2), recorded (2), future (2), provider (2), securityweek (2), many (2), allowed (2), use (2), hackread (2), breaches (2), using (2), critical (2), led (2), cvss (2), flaw (2), console (2), agent (2), hashicorp (2), server (2), lets (2), reused (2), expand (2), south (2), dakota (2), georgia (2), incidents (2), utilities (2), technology (2), scope (2), best (2), psa (2), leak (2), address (2), addresses (2), reveal (2), child (2), sexual (2), imagery (2), according (2), library (2), some (2), recently (2), didn (2), fake (2), check (2), change (2), shape (2), primary (2), same (2), fast (2), trust (2), signals (2), satisfied (2), anyone (2), climbing (2), fund (2), continuous (2), give (2), audit (2), disclosure (2), mitigation (2), standing (2), documented (2), pre (2), observed (2), proof (2), concept (2), cve (2), 000 (2), 200 (2), all (2), 2025 (2), window (2), collapsed (2), rotation (2), long (2), carried (2), targeted (2), extractors (2), production (2), vehicle (2), conscious (2), criminal (2), activity (2), rose (2), 171 (2), destination (2), authentication (2), liability (2), entry (2), min (2), age (2), last (2), ago (2), v12 (2), 868 (2), billion (2), between (2), few (2), spread (2), pipelines (2), container (2), surface (2), adversaries (2), planted (2), persistence (2), directories (2), just (2), operates (2), about (2), monday (2), morning (2), class (2), governance (2), vendors (2), stuff (2), discipline (2), fix (2), come (2), interview (2), enterprises (2), push (2), chains (2), shift (2), whether (2), came (2), does (2), rest (2), hardened (2), execute (2), once (2), lands (2), takeover (2), saw (2), harvested (2), runner (2), installed (2), set (2), both (2), owns (2), precisely (2), past (2), year (2), problem (2), day (2), need (2), pairs (2), finding (2), numbers (2), appear (2), roughly (2), when (2), attackers (2), known (2), puts (2), out (2), called (2), updated (2), shipped (2), there (2), earlier (2), costs (2), nothing (2), community (2), stealing (2), claude (2), files (2), infected (2), caching (2), traced (2), depended (2), turned (2), controlled (2), signature (2), workflow (2), path (2), independently (2), built (2), carrying (2), photoshop (2), alternative (2), affinity (2), today (2), insights (2), menu (2), input (2), field (2), telegram, youtube, linkedin, copyright, make, donation, offers, range, penetration, simulate, network, application, interested, our, please, provide, information, consultation, kitploit, hacking, forgotten, uefi, shims, undermining, boot, hidden, reveals, gov, websites, delivering, kali365, theft, via, device, building, aitm, leaders, know, cfo, playbook, reduce, scaling, tight, labor, market, digest, research, 750, rules, screenshot, verify, see, month, tony, anscombe, major, rats, stealers, safeguarding, 200m, chongluadao, scales, validation, blogs, page, 2276, amsterdam, based, luxury, goods, involving, third, party, logistics, post, appeared, showcasing, products, conference, las, vegas, cisco, talos, authorization, ddos, steal, camera, hacker, unauthenticated, hands, managed, rated, user, later, three, serious, foundation, patched, reported, operational, allegedly, linked, iranian, continues, grow, compare, including, dash, lakera, operant, hiddenlayer, prisma, airs, runtime, protection, techcrunch, implements, feature, theory, masks, sites, visit, offending, image, video, instagram, messenger, threads, pulled, rotated, affected, republished, clean, revealed, productive, meant, holding, counts, reflect, tracking, press, reset, levels, internet, facing, days, emergency, budgeted, operation, committee, metric, defensibility, compensating, controls, registrations, late, wait, classify, workstations, runners, tier, zero, assets, domain, controller, standards, document, reduction, mandate, resistant, multifactor, rights, prefer, short, scoped, ones, machine, countable, began, signed, broken, damage, turn, pulls, blocking, estate, plan, simultaneous, multi, seeded, cascade, jumping, disables, extension, enters, inventory, components, treat, audited, supplier, category, ide, funds, audits, showed, deciding, divide, moves, map, decision, tool, alone, compared, department, defense, forced, raise, game, cmmc, certification, program, better, sell, shipping, source, turns, contractual, pressure, reports, contracts, kayne, mcgladrey, senior, member, ieee, exclusive, starting, obligations, onto, maintainers, start, seeing, trying, contractually, parties, boardroom, next, answers, answer, human, triggered, supposed, weaker, identities, plainly, log, don, hack, machinery, behalf, defenses, wrong, making, harder, while, doing, less, stop, earning, remains, root, cause, kiran, raj, engineer, pattern, cases, defeat, needed, endor, labs, matters, executes, cuts, newer, organization, older, upgrade, slowly, remained, platform, made, factor, mandatory, revoked, old, expiring, added, stored, released, mid, flipped, consequential, postinstall, relies, moment, explicit, approval, spent, hardening, volume, breaks, cycles, cannot, operate, windows, soon, disclosed, moving, towards, mitigating, particular, issue, trajectory, happened, hard, speed, registered, cves, checked, briefing, already, cooldown, second, exploiting, anything, else, kind, focus, around, exploits, exploiter, pointed, resource, teams, underuse, cisa, united, exploited, catalog, weekly, active, government, maintained, probably, safer, guidance, hypothetical, capability, february, cli, pnpm, got, months, either, reject, threshold, argument, turning, minimumreleaseage, setting, blunted, adam, leads, counter, adversary, operations, laid, embargo, things, like, allowing, pull, recent, maybe, delay, whole, pretty, date, won, pulling, onboarded, sort, held, back, gives, catch, poisoning, otherwise, downstream, end, also, work, drops, payloads, machines, reaches, visual, studio, working, directory, anthropic, setup, placed, mean, opens, project, starts, coding, session, assistant, trusts, inspects, actually, libraries, harvesting, authenticate, behind, always, paths, feeding, cacheable, blast, radius, obscure, sits, transitive, popular, rode, corporate, scopes, purpose, layers, tree, reviews, hand, deliveroo, qlik, picsart, among, hits, single, wide, event, landed, environment, could, used, backdoor, victim, became, unwitting, distribution, node, watching, dozens, newly, exfiltrated, repositories, tagged, again, walk, mechanism, becomes, clear, help, analysis, pushed, straight, main, branch, repository, immediately, cut, auditing, integrity, looked, authentic, went, opensearch, requested, oidc, exchanged, minted, sigstore, bundle, fulcio, rekor, tarball, context, cisos, architects, events, message, absorbs, predicted, exact, section, titled, evolve, integration, load, editors, center, threats, tracked, hunting, worry, download, count, paperwork, signatures, cryptographic, industry, prove, forge, way, tuesday, took, maintains, small, key, value, storage, serves, 127, million, times, sibling, midday, counted, 381, together, total, 400, 700, firm, method, easier, gets, faster, reliable, performance, sitemap,
Text of the page (random words):
anyone auditing supply chain integrity the poisoned build looked authentic wiz confirmed the release path independently and in one targeted path documented by jfrog the worm went further inside a github actions run tied to opensearch js it requested an oidc token exchanged it for a publish token and minted a sigstore bundle through fulcio and rekor so the malicious tarball carried provenance generated from the trusted workflow context itself what turned a single account takeover into a registry wide event was the spread once a poisoned package landed in a developer s environment or a build runner its payload harvested every credential it could reach then used any npm publishing tokens it found to backdoor other packages that the victim controlled each compromised maintainer became an unwitting distribution node with aikido watching dozens of newly infected packages appear every few minutes the malware exfiltrated stolen secrets to public github repositories tagged shai hulud here we go again the signature that named the campaign this blast radius reached well beyond obscure utilities because keyv sits as a transitive dependency under many popular tools the worm rode those chains into packages under corporate npm scopes with releases tied to deliveroo qlik and picsart among the confirmed hits developers at those companies never installed keyv on purpose they only depended on something that depended on it layers down a tree no one reviews by hand credential extractors inside the payload reveal what the attackers were actually after and it was never the caching libraries jfrog which traced the compromise across keyv and cacheable and wiz both found the malware harvesting cloud access keys ci secrets and the tokens that authenticate to production infrastructure the package compromise was the vehicle and the cloud behind it was always the destination crowdstrike found cloud conscious criminal activity rose 171 in the first half of 2026 and supply chain compromise is one of the paths feeding it the target was the developer s own tools stealing was not the end of it because the worm also planted itself where developers work wiz found that the malware drops persistence payloads into two directories on machines it reaches one for visual studio code and one named claude the working directory for anthropic s claude code agent the setup files placed there mean the payload can run when a developer opens the infected project in their editor or starts an ai coding session not only at install time this is the developer ecosystem crowdstrike named hit precisely the editor and the ai assistant a developer trusts most and inspects least the fix costs nothing one control would have blunted the worm and it costs nothing adam meyers who leads counter adversary operations at crowdstrike laid it out in a pre release interview under embargo secure the software supply chain he said simple things like not allowing any of your tooling to pull down the most recent dependencies but maybe last week s dependencies the delay is the whole point you re still going to have pretty up to date stuff but you won t have that risk of pulling down something that was updated minutes ago and now you ve just onboarded some sort of malicious tooling a release held back a week gives the security community time to catch a poisoning that would otherwise reach every downstream build within minutes that guidance is not hypothetical npm shipped this capability in february 2026 with cli version 11 10 0 as a setting called min release age pnpm got there five months earlier with minimumreleaseage either one lets a team reject any package version published more recently than a threshold they set the keyv worm is the argument for turning it on meyers pairs the cooldown with a second discipline patch what attackers are exploiting before anything else you need to kind of focus your vulnerability mitigation and patching around the exploits that are known to the exploiter he told venturebeat he pointed to a resource most teams underuse cisa here in the united states puts out something called the known exploited vulnerability catalog updated weekly with flaws confirmed under active attack government maintained and free if you patch those vulnerabilities first you re going to probably be safer meyers put hard numbers to the speed problem numbers that do not appear in the published report all of 2025 saw roughly 48 200 vulnerabilities registered as cves when he checked the week before the briefing 2026 had already reached 43 000 that volume breaks monthly patch cycles they cannot operate in 30 day patch windows he told venturebeat as soon as a vulnerability is disclosed they need to be moving towards patching or mitigating that particular issue crowdstrike s report pairs that trajectory with a finding that 88 of the exploitation it observed against vulnerabilities with a public proof of concept happened inside 48 hours of the code going public github hardened half the problem github which owns npm has spent the past year hardening the registry against precisely this class of attack the platform made two factor authentication mandatory for publishing revoked old never expiring access tokens and added trusted publishing so build systems push without stored credentials then in npm version 12 released in mid 2026 it flipped the most consequential default the preinstall install and postinstall hooks that most registry malware relies on to execute the moment a package lands now require explicit approval that change matters directly here because the keyv worm executes through a preinstall script and npm 12 cuts both ways jfrog confirmed that on npm 12 or newer where preinstall hooks are off by default the malware does not run at install time every organization still on an older npm and most enterprises upgrade slowly remained exposed github s defenses hardened the wrong half of the attack more than the right one making it harder for a malicious package to execute once it lands while doing less to stop an attacker from earning the right to publish account takeover remains the root cause kiran raj a security engineer at endor labs said he saw the same pattern an npm publishing token stolen and reused in most cases a ci or service account token harvested from a build runner that had itself installed a poisoned dependency the worm never had to defeat provenance it needed one set of valid credentials and npm s own publishing automation did the rest provenance attestation answers whether a package came from the pipeline it claims it does not answer whether the human or token that triggered that pipeline was supposed to identity governance who can publish and what their credentials can reach is the weaker control crowdstrike names abuse of legitimate developer identities as the primary entry point for supply chain compromise meyers put it plainly they log in they don t hack in he said the keyv maintainer s account was that identity and the trusted publishing machinery did the rest on the attacker s behalf why the boardroom is next the pressure to fix this will not come only from threat reports it is about to come through contracts kayne mcgladrey a senior member of the ieee told venturebeat in an exclusive interview that enterprises are starting to push software security obligations onto the vendors and maintainers in their supply chains we re going to start seeing companies trying to contractually shift liability to other parties in their supply chain he told venturebeat we re using your technology but we want you to do the security for it he compared it to how the department of defense forced its vendors to raise their game through the cmmc certification program get better at cybersecurity if you want to sell us stuff for any company shipping software on open source dependencies that turns provenance identity and patch discipline into contractual exposure what to do monday morning for a security team deciding what to do about this on monday morning the actions divide into five moves that map to the five ways this attack class operates each is a governance decision a board can fund and audit not a tool a developer installs alone how the attack operates what the keyv worm showed what the board funds and audits the developer ecosystem is the target crowdstrike names package registries ci cd pipelines container registries and ide extensions as the surface adversaries hit directly the keyv payload planted persistence hooks in developer editor and ai tooling directories not just the package require provenance attestation and trusted publishing before any dependency or editor extension enters a build give the board a standing inventory of registries pipeline components and extensions in scope treat developer tooling as an audited supplier category automation makes the spread fast one stolen credential seeded a cascade that reached at least 868 packages and two billion monthly installs in hours jumping between organizations every few minutes the worm ran through a preinstall script the install time default npm v12 disables turn on npm s min release age so tooling pulls last week s versions not releases published minutes ago require npm v12 or install script blocking across the build estate plan for simultaneous multi package compromise in resilience testing identity is the entry point the attack began with one hijacked github maintainer account provenance signed the poisoned releases because they ran through the maintainer s own pipeline valid credentials not a broken control did the damage mandate phishing resistant multifactor authentication for every maintainer with publish rights prefer short lived scoped tokens over long lived ones report developer and machine identity coverage to the board as a countable liability the cloud is the real destination the payload carried targeted extractors for cloud access keys ci secrets and production infrastructure tokens the package compromise was the vehicle cloud conscious criminal activity rose 171 in the first half of 2026 classify developer workstations and ci runners as tier zero assets with domain controller rotation standards document cloud credential rotation in hours after any supply chain exposure report long lived cloud keys with reduction targets the patch window has collapsed crowdstrike observed 88 of exploitation with a public proof of concept inside 48 hours meyers put 2026 cve registrations at 43 000 by late july against 48 200 for all of 2025 the keyv worm was live within hours with no cve to wait for reset patch service levels for internet facing systems from days to hours and fund continuous emergency patching as a budgeted operation give the audit committee time from disclosure to mitigation as a standing metric build defensibility on documented pre patch compensating controls package counts reflect aikido and jfrog tracking as of august 4 and were climbing at press time the keyv worm will be contained compromised versions pulled stolen tokens rotated affected packages republished clean what will not change is the shape of the exposure it revealed the developer ecosystem is now a primary target the automation that makes it productive is the same automation that makes a worm fast and the trust signals meant to secure it can be satisfied by anyone holding the right credentials security venturebeat read more https www backbox org wp content uploads 2018 09 website_backbox_text_black png 0 0 admin https www backbox org wp content uploads 2018 09 website_backbox_text_black png admin 2026 08 05 17 14 15 2026 08 05 17 14 15 the shai hulud npm worm didn t fake its security check it earned a legitimate one meta ran ads that contained ai generated child sexual abuse imagery august 5 2026 in general news more than 50 offending image and video ads were published across facebook instagram messenger or threads according to meta s ad library data some ran as recently as this week security latest read more https www backbox org wp content uploads 2018 09 website_backbox_text_black png 0 0 admin https www backbox org wp content uploads 2018 09 website_backbox_text_black png admin 2026 08 05 17 14 13 2026 08 05 17 14 13 meta ran ads that contained ai generated child sexual abuse imagery psa apple s private relay can leak your real ip address august 5 2026 in general news a bug in how apple implements its private relay feature which in theory masks users ip addresses from the sites they visit can reveal users real ip addresses security news techcrunch read more https www backbox org wp content uploads 2018 09 website_backbox_text_black png 0 0 admin https www backbox org wp content uploads 2018 09 website_backbox_text_black png admin 2026 08 05 17 14 11 2026 08 05 17 14 11 psa apple s private relay can leak your real ip address 5 best ai detection response platforms for 2026 august 5 2026 in general news compare ai detection response platforms for 2026 including dash lakera operant ai hiddenlayer and prisma airs for runtime threat protection and response hackread cybersecurity news data breaches ai and more read more https www backbox org wp content uploads 2018 09 website_backbox_text_black png 0 0 admin https www backbox org wp content uploads 2018 09 website_backbox_text_black png admin 2026 08 05 17 14 07 2026 08 05 17 14 07 5 best ai detection response platforms for 2026 cyberattacks on water systems expand to 12 states as south dakota georgia announce incidents august 5 2026 in general news water utilities in at least 12 states have reported cyberattacks on their operational technology as the scope of a campaign allegedly linked to iranian hackers continues to grow the record from recorded future news read more https www backbox org wp content uploads 2018 09 website_backbox_text_black png 0 0 admin https www backbox org wp content uploads 2018 09 website_backbox_text_black png admin 2026 08 05 15 50 35 2026 08 05 15 50 35 cyberattacks on water systems expand to 12 states as south dakota georgia announce incidents veeam terraform mcp django patch critical flaws led by cvss 10 0 cross tenant bug august 5 2026 in general news hashicorp veeam and the django software foundation have patched 11 vulnerabilities across terraform mcp server veeam service provider console and django the three most serious an unauthenticated flaw in veeam s console that hands over a managed agent s credentials rated 9 5 a cross tenant flaw in hashicorp s mcp server that lets one user s terraform token be reused for later users the hacker news read more https www backbox org wp content uploads 2018 09 website_backbox_text_black png 0 0 admin https www backbox org wp content uploads 2018 09 website_backbox_text_black png admin 2026 08 05 15 50 33 2026 08 05 15 50 33 veeam terraform mcp django patch critical flaws led by cvss 10 0 cross tenant bug i m allowed hackers use simple claims to bypass ai guardrails august 5 2026 in general news cisco talos found hackers using simp...
|