Security researchers have confirmed a critical bypass in NPM's defense mechanisms ("PackageGate") that allows threat actors to execute arbitrary code via Git dependencies. Unlike previous "unconfirmed" reports, this vulnerability is reproducible and actively negates protections implemented after the Shai Hulud attacks. While Bun and PNPM have released patches, NPM currently maintains this is "expected behavior," leaving standard users exposed.
Vulnerability Details
Affected Product: NPM
Exploitation Status: Confirmed / Proof-of-Concept Available
Risk & Impact
Triage: High urgency due to potential for widespread supply chain attacks.
Attack Vector: By exploiting weaknesses in how NPM handles Git dependencies, attackers can bypass security measures.
Ease of Exploit: To be determined.
Action Plan
Immediate Action: Implement dependency review of all software leveraging the npm package ecosystem.
Workaround: Pin npm package dependency versions to known safe releases.
Detection: Check for package-lock.json or yarn.lock files to identify affected packages. Monitor for anomalous network behavior.
Relevant professional terms
Supply Chain Attack
A cyberattack that targets vulnerabilities in the supply chain, aiming to compromise systems by exploiting relationships between organizations.
Git Dependencies
Software packages or libraries that are managed and retrieved using the Git version control system as part of a project's dependencies.
CISA has flagged a critical VMware vCenter Server vulnerability, **CVE-2024-37079**, as actively exploited in the wild, requiring federal agencies to patch their systems. The vulnerability allows for remote code execution and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
Vulnerability Details
Affected Product: VMware vCenter Server
Identifier: CVE-2024-37079
CVSS Score: 9.8 (Critical)
Exploitation Status: Actively Exploited
Risk & Impact
Triage: Immediate patching is crucial for all affected systems.
Attack Vector: Attackers can send specially crafted network packets to vulnerable vCenter instances.
Ease of Exploit: Exploitation can lead to remote code execution without authentication.
Action Plan
Immediate Action: Apply mitigations per vendor instructions.
Workaround: If patches are unavailable, discontinue use of the product.
Detection: Monitor network traffic for suspicious activity and review security logs for potential indicators of compromise.
Relevant professional terms
Remote Code Execution (RCE)
The ability to execute arbitrary code on a remote computer.
Heap Overflow
A type of buffer overflow where the heap, a region of memory used for dynamic memory allocation, is overwritten.
The Russian state-sponsored Sandworm APT is blamed for a cyberattack on Poland's power grid in late 2025. The attack deployed data-wiping malware, but no successful disruption occurred.
Key TTPs
Execution: The attackers deployed a wiper, named DynoWiper, to wipe data.
Defense Evasion: Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.
Campaign Analysis
The attack occurred on the 10th anniversary of Sandworm's attack on the Ukrainian power grid. Sandworm continues to target critical infrastructure sectors, especially in Ukraine.
Targeting & Infrastructure
Target Profile: Poland's energy infrastructure, including two combined heat and power (CHP) plants and a renewable energy management system.
Relevant Terms
APT: An Advanced Persistent Threat (APT) is a sophisticated, long-term cyberattack targeting specific entities.
Data Wiper: A data wiper is a type of malware designed to erase data from a system, often with the intent to disrupt operations.
The Stanley malware toolkit, offered on a cybercrime forum for $2,000-$6,000, enables threat actors to conduct phishing attacks via website spoofing. The toolkit is designed to create Chrome extensions that bypass Google Store validation, allowing for the delivery of attacker-controlled content while displaying legitimate URLs.
Key TTPs
Initial Access: Distribution via Chrome Web Store, .exe silent installer, or manual sideloading.
Execution: The malware uses a Chrome extension disguised as a notes/bookmarks app ("Notely") to inject malicious code.
Defense Evasion: Bypasses Google Store validation to serve phishing pages while displaying legitimate URLs.
Campaign Analysis
The Stanley toolkit marks a new aggressive phase for browser-based attacks, evolving from a low-impact vector to a significant threat. It achieves effective deception by spoofing websites while keeping the address bar intact.
Targeting & Infrastructure
Target Profile: Millions of online users are at risk due to the broad distribution methods.
Infrastructure: C2 infrastructure includes api.notely[.]fun and notely[.]fun/login.
Actionable Intelligence
Domains: api.notely[.]fun, notely[.]fun
Relevant Terms
MaaS (Malware-as-a-Service): A business model where malware developers lease their malware to other actors, enabling them to launch attacks.
Website Spoofing: Creating a fake version of a website to deceive users, often for phishing purposes.
The North Korean Konni group is using AI-generated PowerShell malware to target blockchain developers and engineering teams. The campaign, which uses phishing tactics, has expanded beyond South Korea to include Japan, Australia, and India.
Key TTPs
Initial Access: Phishing emails with malicious links, often delivered via Discord, lead victims to download ZIP archives containing PDF lures and LNK shortcut files.
Execution: LNK files execute PowerShell loaders, which extract and run DOCX documents and CAB archives containing the AI-generated PowerShell backdoor.
Defense Evasion: The malware uses obfuscation, arithmetic operations to build strings, and checks for CPU/RAM thresholds, as well as scans for debugging tools. It also establishes persistence via a scheduled task masquerading as OneDrive.
Campaign Analysis
The use of AI to generate the PowerShell backdoor indicates an evolution in Konni's tactics, allowing for more sophisticated and potentially evasive malware. This campaign demonstrates a broader targeting scope across the APAC region, moving beyond Konni's traditional focus on South Korea.
Targeting & Infrastructure
Target Profile: Software developers and engineering teams with expertise in blockchain-related resources and infrastructure in Japan, Australia, and India.
Infrastructure: Discord is used to host malicious ZIP files, and compromised WordPress websites are used to distribute malware and for C2 infrastructure.
Relevant Terms
PowerShell: A task automation and configuration management framework from Microsoft, consisting of a command-line shell and associated scripting language.
Spear-phishing: A targeted phishing attack aimed at specific individuals or organizations, often using personalized information to increase the likelihood of success.
Threat actors are using "as-a-service" phishing kits to conduct real-time voice phishing (vishing) attacks, posing as IT support to trick victims into divulging credentials. These kits enable attackers to bypass multi-factor authentication (MFA) by manipulating the authentication flow in real time.
Key TTPs
Initial Access: Threat actors perform reconnaissance on targeted employees, gathering information about applications used and IT support phone numbers, then use spoofed numbers to call victims.
Execution: Victims are directed to fraudulent websites resembling legitimate Okta, Microsoft, or Google login pages where they enter their credentials.
Defense Evasion: The phishing kits allow attackers to control the victim's browser in real-time, bypassing MFA by synchronizing the fake login page with the attacker's instructions.
Campaign Analysis
These attacks represent an evolution in cybercrime, moving beyond static phishing pages to interactive interfaces. The real-time manipulation and social engineering make these attacks highly effective at bypassing traditional security measures.
Targeting & Infrastructure
Target Profile: Employees of organizations using Okta SSO, Google, Microsoft and cryptocurrency platforms are targeted.
Infrastructure: The attackers utilize custom phishing kits sold as a service, featuring real-time control panels and the ability to manipulate authentication flows.
Actionable Intelligence
Domains: googleinternal[.]com, mygoogle[.]com
Relevant Terms
Vishing: A social engineering attack conducted via phone calls, where attackers attempt to trick victims into divulging sensitive information.
MFA: Multi-Factor Authentication, a security system that requires more than one method of authentication to verify a user's identity.
The rise of offensive AI is transforming cyberattack strategies, making them more sophisticated and harder to detect, requiring a combined defensive approach. Google's Threat Intelligence Group reports adversaries now use Large Language Models (LLMs) to conceal code and generate malicious scripts.
Key Findings
Adversaries are using Large Language Models (LLMs) to conceal code and generate malicious scripts on the fly.
In November 2025, Anthropic reported the first known "AI-orchestrated cyber espionage campaign," where AI autonomously executed attacks from initial access to data exfiltration.
Attackers use steganography in ClickFix-related attacks, hiding malware within image files to bypass signature-based scans.
The Bottom Line
Organizations must adapt to the evolving threat landscape by moving beyond legacy defenses like Endpoint Detection and Response (EDR). The increasing sophistication and automation of attacks, particularly through AI-driven methods, necessitate a proactive and integrated security strategy. This includes enhanced monitoring of AI API activity, stricter access controls, and continuous updates to endpoint protection measures to effectively counter these adaptive threats.
Relevant Terms
Steganography: The practice of concealing a file, message, image, or video within another file, message, image, or video.
Offensive AI: The malicious use of artificial intelligence technologies to carry out cyber attacks.