31 july 2026 · ransomware and cybercrime · vulnerabilities and patching
The npm maintainer account North Korea phished, and the four packages it unlocked
Amazon has linked four npm supply chain compromises, including debug, chalk and axios, to a North Korea-linked group that phished a single trusted maintainer. Plus: an actively exploited hardcoded credential in Cisco's firewall manager, ShinyHunters' extortion claim against EY, and new NCSC guidance on surviving a disruptive cyber-attack.
Read the full five minutes →