npm supply-chain attacks escalate; Zimbra RCE, Android malware evolves
ID: 3a5956ed-3a9d-50ca-863a-dd2d4fb51dbd
STIX ID: report--3a5956ed-3a9d-50ca-863a-dd2d4fb51dbd
Feed Name: defend.network
Three high-severity active threats demand immediate action: a compromised jscrambler npm package (v8.14.0) that executes a malicious preinstall hook to drop a cross-platform native infostealer; a critical stored XSS in Zimbra Classic Web Client that can run arbitrary code when users view crafted emails; and a RedHook Android variant abusing Wireless ADB to obtain shell-level privileges without a connected computer. The briefing also notes separate China- and India-aligned espionage campaigns against the Balochistan Police and the FBI seizure of NetNut/Popa infrastructure; recommended responses include urgent patching, auditing npm dependencies and lockfiles, secret rotation, disabling wireless debugging, and enhanced monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
