logo

Trojanized npm packages, AWS credential leak, Microsoft Defender driver abuse

ID: 104c6744-6f45-5743-a95b-1103cea9141a

STIX ID: report--104c6744-6f45-5743-a95b-1103cea9141a

Feed Name: defend.network

Threat Score
85/100

Date Published: 2026-08-22

Date Updated: 2026-08-22

Author: defend.network

...
...

This high‑level briefing reports multiple active and high‑risk threats: 14 trojanized npm packages delivering an AI‑assisted RedC2 Linux backdoor, a technique to weaponize Microsoft Defender’s signed boot driver for kernel‑level deletion of security software, over 9,300 publicly exposed AWS access keys still valid, a Microsoft Teams phishing campaign distributing the SynkLoader credential‑stealer, and three CISA‑listed actively exploited vulnerabilities (TrueConf and MLflow); urgent remediation actions (dependency audits, key rotation, patching, and phishing defenses) are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.