North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages

The North Korean threat actors behind the ongoing Contagious Interview campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail malware, as well as a new remote access trojan (RAT) loader.
“These latest samples employ hexadecimal string encoding to evade automated detection systems and manual code audits, signaling a variation

The Hacker News – ​Read More

NSA Chief Ousted Amid Trump Loyalty Firing Spree

Plus: Another DOGE operative allegedly has a history in the hacking world, and Donald Trump’s national security adviser apparently had way more Signal chats than previously known.

Security Latest – ​Read More

Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data

Cybersecurity researchers have uncovered malicious libraries in the Python Package Index (PyPI) repository that are designed to steal sensitive information.
Two of the packages, bitcoinlibdbfix and bitcoinlib-dev, masquerade as fixes for recent issues detected in a legitimate Python module called bitcoinlib, according to ReversingLabs. A third package discovered by Socket, disgrasya, contained a

The Hacker News – ​Read More

Maryland pharmacist used keyloggers to spy on coworkers for a decade, victim alleges

A Maryland pharmacist installed spyware on hundreds of computers at a major teaching hospital and recorded videos of staff over the course of a decade, a class-action lawsuit alleges.

The Record from Recorded Future News – ​Read More

Cisco: Fine-tuned LLMs are now threat multipliers—22x more likely to go rogue

Cisco Reveals Fine-Tuned LLMs Evade Controls, Mimic Insider Threats With 22x More Success


Cisco warns LLMs fine-tuned for business are now being weaponized. Guardrails aren’t failing. They’re being engineered around.Read More

Security News | VentureBeat – ​Read More

CISA Warns: Old DNS Trick ‘Fast Flux’ Is Still Thriving

An old DNS switcheroo technique is still helping attackers keep their infrastructure alive. But is it really a pressing issue in 2025?

darkreading – ​Read More

Gmail Is Not a Secure Way to Send Sensitive Comms: A Friendly Reminder

New end-to-end Gmail encryption alone isn’t secure enough for an enterprise’s most sensitive and prized data, experts say.

darkreading – ​Read More

Port of Seattle says 90,000 people impacted in 2024 ransomware attack

The organization that runs Seattle-Tacoma International Airport and several container terminals said it is sending breach notification letters to those affected by a ransomware attack, including about 71,000 people in Washington state.

The Record from Recorded Future News – ​Read More

Minnesota Tribe Struggles After Ransomware Attack

Hotel and casino operations for the Lower Sioux Indians have been canceled or postponed, and the local health center is redirecting those needing medical or dental care.

darkreading – ​Read More