ModHeader, CrashStealer, Joomla RCE active exploits; npm supply-chain risk
ID: e91f1764-2d45-5c79-9aa8-2a801ba556de
STIX ID: report--e91f1764-2d45-5c79-9aa8-2a801ba556de
Feed Name: defend.network
This briefing describes multiple high-risk incidents: ModHeader was removed from browser stores after a dormant browsing-history collector affecting ~1.6M users was discovered; CrashStealer, a notarized macOS infostealer, is impersonating Apple crash reporting to steal credentials and wallets; CISA warns of active RCE exploitation in Joomla iCagenda and Balbooa Forms via arbitrary uploads; the Jscrambler npm package was backdoored in a supply-chain compromise; and Lidl disclosed a service-provider breach affecting customers in Germany, Belgium, and the Netherlands. Recommended actions include patching, third-party audits, dependency checks, removing suspicious extensions, rotating credentials, and monitoring logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
