Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets

The second wave of the Shai-Hulud supply chain attack has spilled over to the Maven ecosystem after compromising more than 830 packages in the npm registry. The Socket Research Team said it identified a Maven Central package named org.mvnpm:posthog-node:4.18.1 that embeds the same two components associated with Sha1-Hulud: the “setup_bun.js” loader and the main payload […]

Continue Reading

Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist

South Korea’s financial sector has been targeted by what has been described as a sophisticated supply chain attack that led to the deployment of Qilin ransomware. “This operation combined the capabilities of a major Ransomware-as-a-Service (RaaS) group, Qilin, with potential involvement from North Korean state-affiliated actors (Moonstone Sleet), leveraging Managed Service Provider (MSP) compromise as […]

Continue Reading

Alphabet hits record highs, Burry’s AI concerns, Ukraine peace plan and more in Morning Squawk

Jensen Huang, chief executive officer of Nvidia Corp., during the US-Saudi Investment Forum at the Kennedy Center in Washington, DC, US, on Wednesday, Nov. 19, 2025. Stefani Reynolds | Bloomberg | Getty Images This is CNBC’s Morning Squawk newsletter. Subscribe here to receive future editions in your inbox. Here are five key things investors need to know […]

Continue Reading

iQOO 15 Review: Big Steps Forward

The iQOO 15 is almost at par with other 2025 flagships, such as the OnePlus 15, the Oppo Find X9, and the Realme GT 8 Pro, in terms of pricing. It aims to close the gap with its competitors. The brand, however, isn’t attempting to reinvent the flagship formula but to refine the experience in […]

Continue Reading

Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps

Nov 26, 2025Ravie LakshmananBrowser Security / Cryptocurrency Cybersecurity researchers have discovered a new malicious extension on the Chrome Web Store that’s capable of injecting a stealthy Solana transfer into a swap transaction and transferring the funds to an attacker-controlled cryptocurrency wallet. The extension, named Crypto Copilot, was first published by a user named “sjclark76” on […]

Continue Reading

Uber rolls out driverless robotaxis in Abu Dhabi

Driverless WeRide robotaxis for Uber. Courtesy: Uber Uber on Wednesday rolled out fully driverless rides in its fourth market, launching the service in Abu Dhabi in partnership WeRide, a Chinese autonomous vehicle company. The ride-hailing company said the launch in the United Arab Emirates capital represents the first driverless robotaxi service in the Middle East. […]

Continue Reading