News Score: Score the News, Sort the News, Rewrite the Headlines

Unverified npm Account Takeover Vulnerability For Sale on Dark Web Forum - Socket

Dark Web Informer is reporting a threat actor is selling a critical, unverified npmjs vulnerability that would allegedly allow for account takeover. BreachForums member Alderson1337 claims to have found a vulnerability that would enable the following:Targeting npm accounts of specific organization employees to inject undetectable backdoors into the packages they use. Once these packages are updated, all organization devices could be compromised.Targeting npm accounts of developers whose packages...

Read more at socket.dev

© News Score  score the news, sort the news, rewrite the headlines