Researchers find several packages in the @redhat-cloud-services npm namespace shipped malware targeting credentials for GitHub Actions, AWS, GCP, and others (Rohan Prabhu/Step Security Blog)
https://www.stepsecurity.io/blog/multiple-redhat-cloud-servi…
Days after Daily Mail Implicates Stephen Miller in Alex Pretti Murder, Daily Mail Responds with Boobies (emptywheel)
https://emptywheel.net/2026/03/31/days-after-daily-mail-implicates-stephen-miller-in-alex-pretti-murder-daily-mail-responds-with-boobies/
http://www.memeorandum.com/260331/p144#a260331p144
A suspected North Korean hacker has hijacked and modified a popular open source software development tool
to deliver malware that could put millions of developers at risk of being compromised.
On Monday, a hacker pushed malicious versions of the widely used JavaScript library called Axios,
which developers rely on to allow their software to connect to the internet.
The affected library was hosted on npm, a software repository that stores code for open source projects…
Google Threat Intelligence Group (GTIG) has linked the recent axios NPM supply chain attack to a suspected North Korean threat actor, UNC1069 (and not TeamPCP).
https://techcrunch.com/2026/03/31/hacker-hijacks-axios-open-source-proj…
Google attributes the supply chain attack on HTTP client Axios to a suspected North Korean threat actor it calls UNC1069 (Lorenzo Franceschi-Bicchierai/TechCrunch)
https://techcrunch.com/2026/03/31/hacker-hijacks-axios-open-source-…
Fun, which builds fiat and crypto payment rails for platforms like Polymarket and Aave, raised a $72M Series A in January, co-led by Multicoin and SignalFire (Ben Weiss/Fortune)
https://fortune.com/2026/05/01/fun-series-a-fundraise-multicoin-capital-signal…
#TGIQF: Das Quiz rund um Spam-E-Mails
So lange wie das WWW gibts auch die SPAM-Nachrichten, die ungefragt das E-Mail-Postfach verstopfen. Wir haben ein kleines Quiz dazu.