Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Tuesday, September 9, 2025

Major npm compromise; HTTP Request Signature

https://isc.sans.edu/podcastdetail/9604

Major npm compromise

A number of high-profile npm libraries were compromised after developers fell for a phishing email. This compromise affected libraries with a total of hundreds of millions of downloads a week.

https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y


https://github.com/orgs/community/discussions/172738


https://github.com/chalk/chalk/issues/656#issuecomment-3266894253

https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised

HTTP Request Signatures

It looks like some search engines and AI bots are starting to use the HTTP request signature. This should make it easier to identify bot traffic.

https://isc.sans.edu/diary/HTTP+Request+Signatures/32266

SANS Internet Storm Center StormCast Monday, September 8, 2025

YARA to Debugger Offsets; SVG JavaScript Phishing; FreePBX Patches

https://isc.sans.edu/podcastdetail/9602

From YARA Offsets to Virtual Addresses

Xavier explains how to convert offsets reported by YARA into offsets suitable for the use with debuggers.

https://isc.sans.edu/diary/From+YARA+Offsets+to+Virtual+Addresses/32262

Phishing via JavaScript in SVG Files

Virustotal uncovered a Colombian phishing campaign that takes advantage of JavaScript in SVG files.

https://blog.virustotal.com/2025/09/uncovering-colombian-malware-campaign.html

FreePBX Patches

FreePBX released details regarding two vulnerabilities patched last week. One of these vulnerabilities was already actively exploited.

https://github.com/FreePBX/security-reporting/security/advisories/GHSA-3r47-p39v-vqqf

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive