supply chain attack — Cybersecurity News

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph: Threat Hunting at the Speed of Triage

PCAPGraph is an open-source network investigation and threat hunting tool that transforms packet cap...

Open-Source Network Discovery & Topology Mapping

Open-Source Network Discovery & Topology Mapping

RedSide Security has open-sourced NETMAPPER, a network discovery and visualization tool designed to ...

 RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

RDPGraph: Turn Windows Event Logs into an Interactive RDP Attack Graph

When an incident unfolds and all you have left are Windows event logs, understanding attacker moveme...

Latest Posts

Tensorlake npm Package Compromised: Shai-Hulud Worm Harvests Credentials from Developer Machines

Tensorlake npm Package Compromised: Shai-Hulud Worm Harvests Credentials from Developer Machines

RedSide Security October 08, 2026 Cyber Attacks 16 views

The npm package 'tensorlake' was compromised with the Shai-Hulud credential-stealing worm, allowing attackers to harvest secrets, establish persistence, and execute remote code on developer machines.

Continue reading: Tensorlake npm Package Compromised: Shai-Hulud Wor…
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

RedSide Security October 07, 2026 Cyber Attacks 22 views

Attackers compromised the .gh, .sl, and .as domain registries to obtain unauthorized HTTPS certificates for Google domains, putting any site under those TLDs at risk. Google's systems were not breached, but the incident highlights supply chain vulnerabilities in the web PKI.

Continue reading: Attackers Hijack .gh, .sl, and .as Registries to O…