Product
Multiple Vulnerabilities in Microsoft Development Tools
1 TTPMultiple vulnerabilities in Microsoft development tools allow remote, anonymous attackers to perform privilege escalation, bypass security mechanisms, and perform unauthorized information manipulation or disclosure.
Nimbus Manticore Targets Developers with Node.js-based Cross-Platform RATs
1 rule 3 TTPs 3 IOCsThe Iranian threat actor Nimbus Manticore is distributing NodeRabbit and PollCat cross-platform RATs via trojanized coding challenges on LinkedIn to compromise developer systems.
Shai-Hulud Campaign Activity
20 IOCsTracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.
Shai-Hulud Malware Used in Supply Chain Attack via Compromised npm Packages
3 rules 7 TTPs 3 IOCsThe Shai-Hulud malware was used in a large-scale software supply-chain attack compromising hundreds of packages across open-source software ecosystems by compromising developer secrets and CI/CD pipelines.
Suspicious Execution from VS Code Extension
2 rules 9 TTPsMalicious VS Code extensions can execute arbitrary commands, leading to initial access and subsequent payload deployment on Windows systems.