Please turn JavaScript on
Security Risk Advisors icon

Security Risk Advisors

follow.it gives you an easy way to subscribe to Security Risk Advisors's news feed! Click on Follow below and we deliver the updates you want via email, phone or you can read them here on the website on your own news page.

You can also unsubscribe anytime painlessly. You can even combine feeds from Security Risk Advisors with other site's feeds!

Title: A Leader in Cybersecurity Services - Security Risk Advisors

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  2.2 / day

Message History

OpenSourceMalware published research on September 17, 2026 on WeaselBiscuit, a newly identified Node.js infostealer distributed through malicious npm packages, with packages first seen between September 12 and September 16, 2026. The name is researcher assigned and is not an established family name. The researchers tentatively link it to DPRK based on overlap with Contagious ...


Read full story

Air Security published research on September 17, 2026 describing Plugin4Shell, a high severity remote code execution vulnerability affecting the plugin systems of Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. The vulnerability is a SHA pinning bypass: each agent checks out the pinned commit for a marketplace plugin but never verifies the checkout landed there, so...


Read full story

Huntress investigated two incidents involving Settra, a newer ransomware variant first observed in June 2026. The incidents occurred in July and September across consumer services and retail and manufacturing environments. Huntress could not confirm the initial access method in either case, although separate public reporting has associated Settra activity with compromised VPN...


Read full story

Zscaler ThreatLabz identified Operation RapidRust, a new campaign attributed to the Pakistan-nexus threat actor APT36 targeting government and defense organizations in India and Afghanistan. Observed activity includes several newly identified tools: RUSTYSHADE, a Rust-based Windows backdoor; RUSTYMOVE, a removable-media propagation tool; and PSNATCH and BASHNATCH, file-steali...


Read full story

CISA released new guidance on using cyber decoys to improve detection and response, particularly after an attacker has already gained an internal foothold. The guidance positions decoys as a complementary control within Zero Trust architectures, where organizations assume compromise is possible and continuously verify activity. CISA distinguishes among decoys such as tripwire...


Read full story