A compromised Jscrambler npm package containing infostealer malware was distributed by attackers in the npm registry and downloaded nearly 1,500 times.
Google and Microsoft pulled the 1.6-million-times-installed header-editing extension ModHeader after researchers discovered a dormant browsing-history-collector component.
The IHK Regensburg emphasizes that NIS2 compliance and cybercrime prevention are closely intertwined and require a strengthened governance role for management.
AI-powered Windows vulnerability detection shows success at Microsoft, but raises questions about operating costs and carbon footprint that must be weighed against sustainability goals.
The Commission defines binding interpretation guidelines for the resilience requirements of the NIS2 Directive and thereby clarifies the implementation obligations for critical infrastructure operators.
Automated attack techniques accelerate vulnerability exploitation while traditional patch processes lag behind, and trusted software can become a threat.
The 15-year-old Linux kernel vulnerability GhostLock (CVE-2026-43499) enables root access via local threading calls on nearly all distributions, while patch distribution remains irregular.
CISA took over 48 hours to invalidate leaked AWS keys, ignored nine automatic security alerts, and had no defined incident reporting procedures for its own infrastructure.