#ResearchSaturday: @ashlee_benge of @ReversingLabs shares research "Operation Brainleeches: Malicious npm packages fuel supply chain & phishing attacks." Reecently discovered over a dozen malicious packages published to npm open source repository. Listen: https://t.co/kM1wkqqdt0
The @ReversingLabs#research team has identified a novel attack on #PyPI using compiled Python #code to evade detection — possibly the first attack to take advantage of PYC file direct execution. https://t.co/d4LasDJjB8
Researchers @reversinglabs have been analyzing the attack on the @3CX#3CXDesktopApp, especially the d3dcompiler_47.dll. and ffmpeg.dll file, two malicious files pushed in the compromised MSI installer used in this attack.
If you use health or fitness data tracking apps of any kind, you should evaluate what those apps say about you and how the data they collect could be used against you.
In a change of pace from more technical threat analysis, Jon Munshaw and I discuss rapidly changing health data privacy laws and what they mean for you (yes, you, who thinks they have nothing to hide) in the latest @TalosSecurity blog
https://t.co/O5DITjmuH5
If you're a Ukrainian organization interested in support from Cisco and Talos, we're offering Secure Endpoint and Umbrella for free. We're also offering 24/7 managed threat hunting by Talos experts, also for free. Please reach out via any of our public channels.
Today is Ukraine Independence Day -- so @dkorzhevin, JJ Cummings and myself had a chat with @hazeburton about Talos' continuing efforts in the region. The US media coverage has slowed recently but as long as the war is ongoing, Talos will continue our support.
Talos is taking over Cisco Twitter and we want to first say that we continue to proudly support the people of Ukraine by directly defending more than 30 critical infrastructure and government organizations, free of charge.