Skip to main content

Topic

Emerging Issue

Featured image for Axios npm package vulnerability incident blog post
Apr 1, 2026

Learn what happened with the Axios npm package vulnerability, how to confirm exposure to malicious versions, and how Tanium Guardian can help investigate.

Featured image for Claude Code source exposure blog post
Mar 31, 2026

Inside the npm packaging mistake that exposed half a million lines of Claude Code.

Featured image for CVE-2025-47813 Wing FTP Server vulnerability blog post
Mar 19, 2026

CISA KEV‑listed CVE‑2025‑47813 exposes Wing FTP Server install paths used in attack chains. Learn which versions are affected and how to remediate.

Desktop featured image: CTI blog 4 - wide
Feb 2, 2026

The Notepad++ update process was compromised by a supply chain attack, and users are strongly advised to upgrade to version 8.8.9 or later to ensure their security.

Tanium Guardian Spotlight - IDE Extensions
Jan 12, 2026

User-installable extensions for Visual Studio Code, Cursor, and other Integrated Development Environments are an increasingly exploited attack vector, with new malicious extensions discovered almost weekly. Do you have visibility and control?

Desktop featured image: CTI blog 1
Jan 7, 2026

SantaStealer spreads via Telegram and underground forums, the BlackForce phishing kit targets major brands, and Ink Dragon launches new attacks

Desktop featured image: CTI blog 2
Dec 16, 2025

Shanya PaaS spreads among ransomware groups, GrayBravo expands its footprint, and Storm-0249 exploits EDR processes to hide malicious activity

Desktop featured image: CTI blog 4 - wide
Dec 10, 2025

Hybrid 2FA phishing threatens enterprises, RomCom uses SocGholish to deploy Mythic Agent malware, and MuddyWater targets critical infrastructure with evolving tactics

Desktop featured image: CTI blog 3 - wide
Nov 18, 2025

Whisper Leak targets remote language models, @acitons/artifact targets GitHub Actions users, and Quantum Route Redirect simplifies phishing

Desktop featured image: CTI blog 1 - wide
Nov 14, 2025

Actors exploit RMM tools to target trucking and logistics companies, SesameOp uses the OpenAI Assistants API for C2 communications, and Google warns of rising adversary AI adoption in 2026

Desktop featured image: CTI blog 2 - wide
Nov 5, 2025

Learn about DragonForce expanding, Qilin rising as a global ransomware threat, and Water Saci spreading through WhatsApp.

Desktop featured image: CTI blog 4 - wide
Oct 28, 2025

Famous Chollima combines BeaverTail and OtterCookie, COLDRIVER deploys three new malware families, and Vidar Stealer 2.0 demonstrates upgraded capabilities