


Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys
Read More A new set of four malicious packages have been discovered in the npm package registry with capabilities to steal cryptocurrency wallet credentials from Ethereum developers. “The packages masquerade as legitimate cryptographic utilities and Flashbots...
CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation
Read More Federal Civilian Executive Branch (FCEB) agencies are being advised to update their Sitecore instances by September 25, 2025, following the discovery of a security flaw that has come under active exploitation in the wild. The vulnerability, tracked as...
TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations
Read More The threat actor behind the malware-as-a-service (MaaS) framework and loader called CastleLoader has also developed a remote access trojan known as CastleRAT. “Available in both Python and C variants, CastleRAT’s core functionality consists of...