CISA issues alert on NPM supply chain compromise involving credential theft and malware
A supply chain attack on NPM has compromised over 500 packages using credential theft and self-propagating malware.
Decision Insights Threat Desk • November 26, 2025
A supply chain attack on NPM has compromised over 500 packages using credential theft and self-propagating malware.
Decision Insights Threat Desk • November 26, 2025
Draytek Vigor routers with DrayOS firmware have a remote code execution flaw in EasyVPN and LAN interfaces enabling attacker control.
Decision Insights Threat Desk • November 26, 2025
Kiwire Captive Portal vulnerabilities include SQL injection, open redirection, and XSS; vendor released fixes are available.
Decision Insights Threat Desk • November 26, 2025
Clevo's UEFI firmware leaked private Boot Guard keys, risking pre-boot firmware integrity on affected systems.
Decision Insights Threat Desk • November 26, 2025
A vulnerability in browsers allows DNS rebinding and CORS header manipulation to enable unauthorized data access.
Decision Insights Threat Desk • November 26, 2025
Password managers in browser extensions face DOM-based clickjacking risks that may expose stored credentials during autofill.