Threats

Malware, attack campaigns, APT groups

GitHub Disables 73 Microsoft Repositories in 105 Seconds After Miasma Worm Compromises Azure Infrastructure and Breaks CI/CD Pipelines

Threats

GitHub Disables 73 Microsoft Repositories in 105 Seconds After Miasma Worm Compromises Azure Infrastructure and Breaks CI/CD Pipelines

GitHub has disabled 73 Microsoft repositories after the Miasma worm infiltrated Azure infrastructure through a compromised contributor account, breaking CI/CD pipelines across the Azure Functions ecosystem and triggering remote code execution on developer machines that opened the infected repos in IDEs and AI coding tools. The attack began on

By Zero Day Wire
Five Eyes Warn Chinese Military Intelligence Recruiting Government and Military Personnel Through Fake Job Offers on LinkedIn and Indeed

Threats

Five Eyes Warn Chinese Military Intelligence Recruiting Government and Military Personnel Through Fake Job Offers on LinkedIn and Indeed

The intelligence agencies of all five Five Eyes nations have issued a joint alert warning that Chinese military intelligence officers are conducting coordinated recruitment campaigns on professional networking platforms, targeting government and military personnel with access to classified or privileged information. The alert — co-authored by the FBI, MI5, the

By Zero Day Wire
Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

Threats

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

A compromised version of the Nx Console extension — a popular VS Code plugin with over 2.2 million installations — was published to the Visual Studio Code Marketplace after an attacker leveraged stolen developer credentials to inject a multi-stage credential stealer into the official nrwl/nx GitHub repository. The malicious

By Zero Day Wire