Sponsor of the Day:
Jerkmate
https://www.csoonline.com/article/4046407/attackers-steal-data-from-salesforce-instances-via-compromised-ai-live-chat-tool.html
Attackers steal data from Salesforce instances via compromised AI live chat tool | CSO Online
Sep 8, 2025 - One of their goals was to access other credentials to compromise other environments.
ai live chatsteal datavia compromisedcso onlineattackers
https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html
Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying cross-platform RAT malware.
axios supply chaincross platform ratvia compromisedattackpushes
https://www.helpnetsecurity.com/2026/04/20/vercel-breached/
Vercel breached via compromised third-party AI tool - Help Net Security
Cloud deployment and hosting platform Vercel has been breached and attackers accessed some of its internal systems.
third party aivia compromisedtool helpvercelbreached
https://www.stepsecurity.io/blog/forcememo-hundreds-of-github-python-repos-compromised-via-account-takeover-and-force-push
ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push -...
The StepSecurity threat intelligence team was the first to discover and report on an ongoing campaign — which we are tracking as ForceMemo — in which an...
github pythonaccount takeoverforce pushforcememohundreds