Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIPopular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
Attackers compromised JavaScript files used by three popular WordPress plugins (PushEngage, OptinMonster, and TrustPulse), injecting malicious code that created unauthorized admin accounts and installed hidden backdoor plugins when site administrators were logged in. The attack specifically targeted authenticated administrators while leaving ordinary site visitors unaffected, demonstrating a sophi
AIOver 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
Over 400 packages in Arch Linux's Arch User Repository (AUR) were compromised this week through hijacked build scripts that deployed credential-stealing malware. The Rust-based infostealer targets developer secrets and can deploy an eBPF rootkit when executed with root privileges to evade detection.
AI400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
Over 400 packages in Arch Linux's Arch User Repository (AUR) were compromised this week when attackers hijacked them and modified build scripts to deploy credential-stealing malware. The malicious payload is a Rust-based binary designed to harvest developer credentials and secrets, with the capability to deploy an eBPF rootkit when executed with root privileges to evade detection.
AIOceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
The Vietnam-aligned threat actor OceanLotus has conducted two cyber espionage campaigns targeting Vietnamese infrastructure companies and stock investors using the SPECTRALVIPER backdoor. The attacks include a prolonged operation against a Vietnamese construction corporation spanning mid-2024 to February 2026, alongside a separate supply chain attack targeting investors.
AIMicrosoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Microsoft temporarily removed several GitHub repositories following a security incident that compromised 73 of its open-source projects with information-stealing malware. The company is conducting an ongoing investigation while prioritizing customer and ecosystem protection, with some repositories restored and others remaining offline during the probe.
AIDriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
DriveSurge, a large-scale initial access broker (IAB) operation, is leveraging a malicious traffic distribution system (TDS) to compromise thousands of legitimate websites. The campaign redirects unsuspecting visitors from trusted sites to malicious destinations that deploy ClickFix and FakeUpdate malware attacks, representing a significant supply chain security threat.
AIMiasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
A supply chain attack dubbed Miasma has compromised Red Hat npm packages (@redhat-cloud-services) to deploy credential-stealing malware and a self-propagating worm on developer systems. The campaign employs Mini Shai-Hulud tactics including install-time execution, credential harvesting, CI/CD pipeline targeting, and encrypted data exfiltration. This incident represents a significant threat to ente
