A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
A new npm supply chain campaign is hiding malware inside ordinary JavaScript package code instead of using the usual ...
IntroductionUntil now, I have been prototyping a 'Shogi Coach AI' that takes the 'best move, evaluation value, and principal variation (PV)' provided by a Shogi engine and passes them to a generative ...
Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG  5 min. Over the past year, GuidePoint’s Threat and Attack Simulation (TAS) team has ...
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by ...
Recently, my way of thinking about learning has changed a little. Until now, I would sometimes think: “If I’m studying JavaScript, I have to understand it properly.” “I’ll probably need statistics ...
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) capable of turning ...
Attackers abuse Node.js to execute malicious scripts and deploy payloads in attacks targeting governments, technology companies, and hotels.
Johann Rehberger’s Python module-shadowing attack achieves remote code execution 60-80 percent of the time against a feature ...
Trigger Point is finally back on ITV, bringing back plenty of drama to our screens as the summer draws to a close and the autumn nights begin to roll in. The series was created and written by Daniel ...