● On the wire
I thought my TV needed Ethernet, but Wi-Fi proved me wrong//Amid Increased Scrutiny, ICE Detention and Deportation Data Goes Dark//Scientists use dual-frequency images to explore black hole plasma physics//NAND shortages could finally ease in 2027, but ADATA warns the DRAM crisis may last another 10 years//Firefighters battle major wildfire as thousands of hectares burn in central Spain//UK PM Burnham: ‘We need to be a cost-of-living government’//Un primo agosto senza fuochi d'artificio?//Chandrasekhar and the Limits of Physics, Part 2: Humiliation//Coinbase says ‘low-risk’ config change behind 50-minute July 14 outage impacting trading, card transactions//Viaggi fuori dall’Europa? Come avere Internet senza pagare il roaming//Any Cheaper alternatives to Offsec Cloud Security Training//LG OLED55B56LA a 719€: il 55 pollici OLED con AI e gaming 4K@120Hz è ai minimi su Amazon//Black Hat USA//Italy’s Meloni slams protesters following clashes in Bologna//A cronometro c'è un solo REmco//I thought my TV needed Ethernet, but Wi-Fi proved me wrong//Amid Increased Scrutiny, ICE Detention and Deportation Data Goes Dark//Scientists use dual-frequency images to explore black hole plasma physics//NAND shortages could finally ease in 2027, but ADATA warns the DRAM crisis may last another 10 years//Firefighters battle major wildfire as thousands of hectares burn in central Spain//UK PM Burnham: ‘We need to be a cost-of-living government’//Un primo agosto senza fuochi d'artificio?//Chandrasekhar and the Limits of Physics, Part 2: Humiliation//Coinbase says ‘low-risk’ config change behind 50-minute July 14 outage impacting trading, card transactions//Viaggi fuori dall’Europa? Come avere Internet senza pagare il roaming//Any Cheaper alternatives to Offsec Cloud Security Training//LG OLED55B56LA a 719€: il 55 pollici OLED con AI e gaming 4K@120Hz è ai minimi su Amazon//Black Hat USA//Italy’s Meloni slams protesters following clashes in Bologna//A cronometro c'è un solo REmco//
AsyncAPI npm supply-chain compromise spreads malware through trusted packages
Top story — Nachrichten

AsyncAPI-npm-Lieferkettenkompromittierung verbreitet Malware über vertrauenswürdige Pakete

Angreifer kompromittierten die AsyncAPI-npm-Organisation und schleusten bösartigen Code in mehrere weit verbreitete Pakete ein, darunter die Pakete generator und specs mit mehr als zwei Millionen wöchentlichen Downloads. Die Malware wurde über einen kompromittierten GitHub-Actions-Workflow ausgeliefert und bei der Installation ausgeführt, wodurch ein routinemäßiges Abhängigkeits-Update zu einem Infektionspfad wurde. Microsoft und andere Forscher sagten, die Nutzlast könne Browser-Zugangsdaten, SSH-Schlüssel, npm-Tokens, AWS-Geheimnisse…

Read the article →
From the newsroom