Over 500 NPM Packages Compromised in Supply Chain Attack via Socket
Over 500 npm packages compromised in a recent supply chain attack involving credential theft and malware propagation per Socket.
Decision Insights Threat Desk • November 18, 2025
Over 500 npm packages compromised in a recent supply chain attack involving credential theft and malware propagation per Socket.
Decision Insights Threat Desk • November 18, 2025
A remote code execution vulnerability was found in Vigor routers by Draytek, allowing attackers to inject commands via HTTP requests.
Decision Insights Threat Desk • November 18, 2025
SynchroWeb's Kiwire Captive Portal has three web vulnerabilities identified, prompting users to update their systems for security.
Decision Insights Threat Desk • November 18, 2025
Clevo's firmware updates revealed private keys for Intel Boot Guard, risking UEFI security on affected systems due to potential exploitation.
Decision Insights Threat Desk • November 18, 2025
A vulnerability in CORS headers across several browsers allows manipulation of policies, enabling attackers to send unauthorized requests. Users should ensure their browsers are updated with the latest patches.
Decision Insights Threat Desk • November 18, 2025
Browser extensions for password management may face clickjacking risks due to DOM manipulation, prompting users to take security measures.