Skip to content
Thursday, June 4, 2026
  • IronWorm Malware Infects 36 Packages In npm Attack
  • Hackers Share Playbook Targeting Vulnerability Gaps
  • Kali365 PhaaS Expands To Target Okta And MAX Messenger
  • Lazarus Group Targets Developers With npm Brandjacking
Newsletter

CyDhaal – Your Daily Dose of Cyber Intelligence

Daily Cyber Threats. Zero Noise

Random News
  • IronWorm Malware Infects 36 Packages In npm Attack
  • Hackers Share Playbook Targeting Vulnerability Gaps
  • Kali365 PhaaS Expands To Target Okta And MAX Messenger
  • Lazarus Group Targets Developers With npm Brandjacking

CyDhaal – Your Daily Dose of Cyber Intelligence

Daily Cyber Threats. Zero Noise

Newsletter
Random News
  • About CyDhaal
  • Newsletter
  • Privacy Policy
Headlines
  • IronWorm Malware Infects 36 Packages In npm Attack

    1 hour ago
  • Hackers Share Playbook Targeting Vulnerability Gaps

    8 hours ago
  • Kali365 PhaaS Expands To Target Okta And MAX Messenger

    8 hours ago
  • Lazarus Group Targets Developers With npm Brandjacking

    8 hours ago
  • Critical Cisco Unified CM Bug Patched With Live Exploits

    8 hours ago
  • Five Eyes Warns: China Targeting LinkedIn Users Again

    8 hours ago
  • China-Linked TA4922 Expands Phishing Across Europe

    8 hours ago
  • Fake ID Marketplace Dismantled By European Police

    8 hours ago
  • Chinese Spies Use Fake Job Ads To Target Military Staff

    12 hours ago
  • Gamaredon Exploits WinRAR Flaw In Ukrainian Spy Attack

    12 hours ago
  • Cyber Espionage
1 hour ago

IronWorm Malware Infects 36 Packages In npm Attack

A sophisticated supply chain attack has compromised 36 npm packages with IronWorm malware, targeting developers’ systems to exfiltrate sensitive data and establish persistent backdoors. The malicious packages received thousands of downloads before detection, affecting developers worldwide who integr

  • Zero Day
8 hours ago

Hackers Share Playbook Targeting Vulnerability Gaps

Cybercriminals are systematically exploiting the operational gaps in enterprise vulnerability management programs rather than solely targeting unpatched systems. Recent threat intelligence reveals attackers focus on scanning windows, patch deployment delays, asset inventory blind spots, and prioriti

  • AI
8 hours ago

Kali365 PhaaS Expands To Target Okta And MAX Messenger

The Kali365 Phishing-as-a-Service (PhaaS) platform has significantly expanded its targeting capabilities beyond Microsoft 365 to include Okta identity services and MAX Messenger communication platform. This evolution represents a dangerous shift in the PhaaS ecosystem, enabling even low-skilled thre

  • Cyber Espionage
8 hours ago

Lazarus Group Targets Developers With npm Brandjacking

The North Korean state-sponsored Lazarus Group has launched a sophisticated npm brandjacking campaign targeting software developers. By creating typosquatted packages that mimic legitimate libraries, the threat actors are distributing malware designed to steal credentials, cryptocurrency wallets, an

IronWorm Malware Infects 36 Packages In npm Attack
  • Cyber Espionage

IronWorm Malware Infects 36 Packages In npm Attack

Hackers Share Playbook Targeting Vulnerability Gaps
  • Zero Day

Hackers Share Playbook Targeting Vulnerability Gaps

Kali365 PhaaS Expands To Target Okta And MAX Messenger
  • AI

Kali365 PhaaS Expands To Target Okta And MAX Messenger

Lazarus Group Targets Developers With npm Brandjacking
  • Cyber Espionage

Lazarus Group Targets Developers With npm Brandjacking

  • Cyber Espionage

IronWorm Malware Infects 36 Packages In npm Attack

CyDhaal Admin1 hour ago011 mins

A sophisticated supply chain attack has compromised 36 npm packages with IronWorm malware, targeting developers’ systems to exfiltrate sensitive data and establish persistent backdoors. The malicious packages received thousands of downloads before detection, affecting developers worldwide who integr

Read More
  • Zero Day

Hackers Share Playbook Targeting Vulnerability Gaps

CyDhaal Admin8 hours ago08 mins

Cybercriminals are systematically exploiting the operational gaps in enterprise vulnerability management programs rather than solely targeting unpatched systems. Recent threat intelligence reveals attackers focus on scanning windows, patch deployment delays, asset inventory blind spots, and prioriti

Read More
  • AI

Kali365 PhaaS Expands To Target Okta And MAX Messenger

CyDhaal Admin8 hours ago08 mins

The Kali365 Phishing-as-a-Service (PhaaS) platform has significantly expanded its targeting capabilities beyond Microsoft 365 to include Okta identity services and MAX Messenger communication platform. This evolution represents a dangerous shift in the PhaaS ecosystem, enabling even low-skilled thre

Read More
  • Cyber Espionage

Lazarus Group Targets Developers With npm Brandjacking

CyDhaal Admin8 hours ago08 mins

The North Korean state-sponsored Lazarus Group has launched a sophisticated npm brandjacking campaign targeting software developers. By creating typosquatted packages that mimic legitimate libraries, the threat actors are distributing malware designed to steal credentials, cryptocurrency wallets, an

Read More
  • Ransomware

Critical Cisco Unified CM Bug Patched With Live Exploits

CyDhaal Admin8 hours ago07 mins

Cisco has released emergency patches for a critical authentication bypass vulnerability (CVE-2024-20272) in Unified Communications Manager (Unified CM) with a CVSS score of 9.8. Public exploit code is now circulating, enabling unauthenticated attackers to execute arbitrary commands with root privile

Read More
  • AI

Five Eyes Warns: China Targeting LinkedIn Users Again

CyDhaal Admin8 hours ago08 mins

The Five Eyes intelligence alliance has issued a fresh warning about renewed Chinese espionage operations targeting government officials, defense contractors, and critical infrastructure workers through LinkedIn. Threat actors are creating sophisticated fake profiles to establish trusted relationshi

Read More
  • AI

China-Linked TA4922 Expands Phishing Across Europe

CyDhaal Admin8 hours ago08 mins

Chinese state-sponsored threat actor TA4922 has broadened its phishing campaign beyond traditional targets, now hitting organizations in the United Kingdom, Germany, Italy, and South Africa. The group deploys sophisticated credential harvesting infrastructure using compromised legitimate domains and

Read More
  • AI

Fake ID Marketplace Dismantled By European Police

CyDhaal Admin8 hours ago08 mins

European law enforcement agencies successfully dismantled a sophisticated online marketplace specializing in fraudulent identity documents used predominantly by migrant smuggling operations. The operation, coordinated across multiple jurisdictions, resulted in arrests, server seizures, and the disru

Read More
  • Cyber Espionage

Chinese Spies Use Fake Job Ads To Target Military Staff

CyDhaal Admin12 hours ago08 mins

The Five Eyes intelligence alliance has issued a joint advisory warning that Chinese state-sponsored threat actors are conducting sophisticated social engineering campaigns using fake job advertisements to target military personnel and defense contractors. These operations aim to extract classified

Read More
  • Cyber Espionage

Gamaredon Exploits WinRAR Flaw In Ukrainian Spy Attack

CyDhaal Admin12 hours ago08 mins

Russian-linked APT group Gamaredon has weaponized a known WinRAR vulnerability (CVE-2023-38831) to deploy sophisticated modular spyware against Ukrainian targets. The campaign leverages malicious archive files disguised as legitimate documents to achieve initial access, followed by multi-stage paylo

Read More
  • 1
  • 2
  • 3
  • …
  • 31

Recent Posts

  • IronWorm Malware Infects 36 Packages In npm Attack
  • Hackers Share Playbook Targeting Vulnerability Gaps
  • Kali365 PhaaS Expands To Target Okta And MAX Messenger
  • Lazarus Group Targets Developers With npm Brandjacking
  • Critical Cisco Unified CM Bug Patched With Live Exploits

Recent Comments

No comments to show.

Archives

  • June 2026
  • May 2026

Categories

  • AI
  • Cyber Espionage
  • Data Breach
  • Malware
  • Others
  • Ransomware
  • Vulnerability
  • Zero Day

You May Have Missed

  • AI

Google Launches Deepfake Call Detection For Android

CyDhaal Admin 2 days ago
  • AI

Why Cryptography Can’t Secure Modern Networks Anymore

CyDhaal Admin 2 days ago
  • Zero Day

PAN-OS GlobalProtect Flaw Under Active Exploitation

CyDhaal Admin 6 days ago
  • Zero Day

Google Leaks Details Of Unfixed Chromium Flaw

CyDhaal Admin 2 weeks ago2 weeks ago
  • Malware

Supply Chain Worm Alert: “Mini Shai-Hulud” Hits Node Ecosystem, Steals CI/CD Secrets at Scale

CyDhaal Admin 2 weeks ago2 weeks ago
  • Cyber Espionage

Gunra Ransomware Expands RaaS After Conti Shift

CyDhaal Admin 3 weeks ago
  • AI

AI-Driven Exploits Collapse Security Response Windows

CyDhaal Admin 2 days ago
  • Zero Day

Google Patches 124 Android Flaws, One Actively Exploited

CyDhaal Admin 2 days ago
Copyright © 2026 CyDhaal. All Rights Reserved. Powered By BlazeThemes.