View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA warns admins to patch actively exploited SharePoint flaws

🚨 ACTIVE EXPLOITS & INCIDENTS

🔓 VULNERABILITIES & CVEs

📋 VENDOR BULLETINS & ADVISORIES

🕵️ THREAT RESEARCH & DEEP DIVES

  • Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware — The Hacker News
    Four npm packages in the @asyncapi namespace were compromised to distribute a multi-stage botnet loader. Affected versions include @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, @asyncapi/generator@3.3.1, and @asyncapi/specs (v6.11.2 and v6.11.2-alpha.1). Developers should audit dependencies and remove these packages immediately.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check