Monthly Archive: September 2025

Warning: Fake npm Package Hijacks Crypto Wallets

Researchers at Socket have uncovered a malicious npm package named nodejs-smtp, masquerading as the widely used nodemailer library (which averages 3.9 million weekly downloads). In reality, the package serves as a tool for covert...

Salesloft Breach Triggers Global Threat Cascade

A large-scale theft of authentication tokens from Salesloft, developer of the corporate chatbot platform, has triggered a chain reaction of threats across digital infrastructure worldwide. According to a warning from Google, the breach affects...

Robot Takeover? Critical Flaw in Pudu Robots Exposed

A security researcher uncovered critical vulnerabilities in the admin panel of Pudu Robotics, China’s largest supplier of commercial service robots. The flaw allowed attackers to redirect robots and issue arbitrary commands. Pudu manufactures over...

Pyramid: Python scripts to evade EDRs

Pyramid: Python scripts to evade EDRs

What is it Pyramid is a set of Python scripts and module dependencies that can be used to evade EDRs. The main purpose of the tool is to perform offensive tasks by leveraging some...

OldGremlin Ransomware Returns to Haunt Russian Businesses

Researchers at Kaspersky Lab have reported the resurgence of ransomware operations by the group OldGremlin, which has once again begun targeting Russian companies. In the first half of 2025, eight major enterprises were compromised,...