• Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

    Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

    The popular HTTP client known as Axios has suffered a supply chain attack after two newly published versions of the npm package introduced a malicious dependency. Versions 1.14.1 and 0.30.4 of Axios have been found to inject “plain-crypto-js” version 4.2.1 as a fake dependency. According to StepSecurity, the two versions were published using the compromised…

    Read More

  • ‘No Kings’ returns to the Gorge

    ‘No Kings’ returns to the Gorge

    GORGE — Thousands of demonstrators across the Columbia River Gorge joined over 8 million nationwide on March 28 for a third “No Kings” day of action, which set records as the largest single-day protest in U.S. history.

    Read More

  • OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

    OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

    A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new findings from Check Point. “A single malicious prompt could turn an otherwise ordinary conversation into a covert exfiltration channel, leaking user messages, uploaded files, and other sensitive content,” the cybersecurity company said in

    Read More

  • ‘No Kings’ photo slideshow: Goldendale

    ‘No Kings’ photo slideshow: Goldendale

    GOLDENDALE — About 80 people occupied the four corners near United Methodist Church in Goldendale on March 28 for a “No Kings” demonstration in protest of the Trump administration.

    Read More

  • ‘No Kings’ photo slideshow: Hood River

    ‘No Kings’ photo slideshow: Hood River

    HOOD RIVER — Roughly 1,000 people gathered in Hood River on March 28 for a third “No Kings” rally in protest of the Trump administration. Demonstrators, many wielding signs or wearing costumes, assembled at the waterfront, before marching downtown to…

    Read More

  • DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials

    DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials

    A new campaign has leveraged the ClickFix social engineering tactic as a way to distribute a previously undocumented malware loader referred to as DeepLoad. “It likely uses AI-assisted obfuscation and process injection to evade static scanning, while credential theft starts immediately and captures passwords and sessions even if the primary loader is blocked,” ReliaQuest researchers…

    Read More

  • ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More

    ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More

    Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention. There’s a bit of everything this week. Persistence plays, legal wins, influence…

    Read More

  • The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

    The State of Secrets Sprawl 2026: 9 Takeaways for CISOs

    Secrets sprawl isn’t slowing down: in 2025, it accelerated faster than most security teams anticipated. GitGuardian’s State of Secrets Sprawl 2026 report analyzed billions of commits across public GitHub and uncovered 29 million new hardcoded secrets in 2025 alone, a 34% increase year over year and the largest single-year jump ever recorded. This year’s findings…

    Read More

  • Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels

    Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels

    Cybersecurity researchers have discovered a remote access toolkit of Russian-origin that’s distributed via malicious Windows shortcut (LNK) files that are disguised as private key folders. The CTRL toolkit, according to Censys, is custom-built using .NET and includes various executables” to facilitate credential phishing, keylogging, Remote Desktop Protocol (RDP) hijacking, and reverse tunneling

    Read More

  • Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign

    Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign

    Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a “complex and well-resourced operation.” The campaigns have led to the deployment of various malware families, including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL

    Read More