Topic
Emerging Issue

Axios npm package compromise: What happened, what matters, and how to respond
Learn what happened with the Axios npm package vulnerability, how to confirm exposure to malicious versions, and how Tanium Guardian can help investigate.

Claude Code source exposure: What enterprises should do next
Inside the npm packaging mistake that exposed half a million lines of Claude Code.

CVE‑2025‑47813: Wing FTP Server vulnerability flagged by CISA
CISA KEV‑listed CVE‑2025‑47813 exposes Wing FTP Server install paths used in attack chains. Learn which versions are affected and how to remediate.

A Supply Chain Attack in Notepad++
The Notepad++ update process was compromised by a supply chain attack, and users are strongly advised to upgrade to version 8.8.9 or later to ensure their security.

IDE extensions: a new persistent risk to your organization
User-installable extensions for Visual Studio Code, Cursor, and other Integrated Development Environments are an increasingly exploited attack vector, with new malicious extensions discovered almost weekly. Do you have visibility and control?

CTI roundup: SantaStealer, BlackForce, Ink Dragon
SantaStealer spreads via Telegram and underground forums, the BlackForce phishing kit targets major brands, and Ink Dragon launches new attacks

CTI roundup: Shanya, GrayBravo, Storm-0249
Shanya PaaS spreads among ransomware groups, GrayBravo expands its footprint, and Storm-0249 exploits EDR processes to hide malicious activity

CTI roundup: Hybrid 2FA phishing, RomCom, MuddyWater
Hybrid 2FA phishing threatens enterprises, RomCom uses SocGholish to deploy Mythic Agent malware, and MuddyWater targets critical infrastructure with evolving tactics

CTI roundup: Whisper Leak, @acitons/artifact, Quantum Route Redirect
Whisper Leak targets remote language models, @acitons/artifact targets GitHub Actions users, and Quantum Route Redirect simplifies phishing

CTI roundup: RMM abuse, SesameOp, Google’s 2026 Cybersecurity Forecast
Actors exploit RMM tools to target trucking and logistics companies, SesameOp uses the OpenAI Assistants API for C2 communications, and Google warns of rising adversary AI adoption in 2026

CTI roundup: DragonForce, Qilin, Water Saci
Learn about DragonForce expanding, Qilin rising as a global ransomware threat, and Water Saci spreading through WhatsApp.

CTI roundup: Famous Chollima, COLDRIVER, Vidar Stealer 2.0
Famous Chollima combines BeaverTail and OtterCookie, COLDRIVER deploys three new malware families, and Vidar Stealer 2.0 demonstrates upgraded capabilities