Robuta

Sponsor of the Day: Jerkmate
https://www.csoonline.com/article/4046407/attackers-steal-data-from-salesforce-instances-via-compromised-ai-live-chat-tool.html Attackers steal data from Salesforce instances via compromised AI live chat tool | CSO Online Sep 8, 2025 - One of their goals was to access other credentials to compromise other environments. ai live chatsteal datavia compromisedcso onlineattackers https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying cross-platform RAT malware. axios supply chaincross platform ratvia compromisedattackpushes https://www.helpnetsecurity.com/2026/04/20/vercel-breached/ Vercel breached via compromised third-party AI tool - Help Net Security Cloud deployment and hosting platform Vercel has been breached and attackers accessed some of its internal systems. third party aivia compromisedtool helpvercelbreached https://www.stepsecurity.io/blog/forcememo-hundreds-of-github-python-repos-compromised-via-account-takeover-and-force-push ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push -... The StepSecurity threat intelligence team was the first to discover and report on an ongoing campaign — which we are tracking as ForceMemo — in which an... github pythonaccount takeoverforce pushforcememohundreds