Trojanized npm packages, AWS credential leak, Microsoft Defender driver abuse
ID: 104c6744-6f45-5743-a95b-1103cea9141a
STIX ID: report--104c6744-6f45-5743-a95b-1103cea9141a
Feed Name: defend.network
This high‑level briefing reports multiple active and high‑risk threats: 14 trojanized npm packages delivering an AI‑assisted RedC2 Linux backdoor, a technique to weaponize Microsoft Defender’s signed boot driver for kernel‑level deletion of security software, over 9,300 publicly exposed AWS access keys still valid, a Microsoft Teams phishing campaign distributing the SynkLoader credential‑stealer, and three CISA‑listed actively exploited vulnerabilities (TrueConf and MLflow); urgent remediation actions (dependency audits, key rotation, patching, and phishing defenses) are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
