Última hora
ARتصاعد التوترات في الشرق الأوسط: هجمات في مضيق هرمز ومأرب وجنوب لبنانARإعلام إيراني: اندلاع حريق في سفينة أخرى بمضيق هرمزARهجوم على ناقلة نفط إماراتية في مضيق هرمز وإيران تعلن عن تقدم في المفاوضاتARتوقيع اتفاقية مكة للدفاع المشترك بين السعودية وتركيا وباكستانARاستهداف سفينة تابعة لأدنوك بصاروخ في مضيق هرمز والإمارات تدين الهجومARمقتل مدنيين وعسكريين بقصف حوثي على مأرب وتحذيرات أممية من عودة الصراعARإيران وعُمان قريبتان من اتفاق على ممر ملاحي جديد عبر هرمزARروسيا تعلن السيطرة على إيفانوفكا وتفصيل خسائر الجيش الأوكرانيARانتقادات واسعة لجياني إنفانتينو بعد مقترح بيع حصص في كأس العالم وانقسام الاتحادات الكرويةARالحوثيون لـCNN: لا نحتاج لأوامر من طهران لتصعيد الصراع مع السعوديةARتصاعد التوترات في الشرق الأوسط: هجمات في مضيق هرمز ومأرب وجنوب لبنانARإعلام إيراني: اندلاع حريق في سفينة أخرى بمضيق هرمزARهجوم على ناقلة نفط إماراتية في مضيق هرمز وإيران تعلن عن تقدم في المفاوضاتARتوقيع اتفاقية مكة للدفاع المشترك بين السعودية وتركيا وباكستانARاستهداف سفينة تابعة لأدنوك بصاروخ في مضيق هرمز والإمارات تدين الهجومARمقتل مدنيين وعسكريين بقصف حوثي على مأرب وتحذيرات أممية من عودة الصراعARإيران وعُمان قريبتان من اتفاق على ممر ملاحي جديد عبر هرمزARروسيا تعلن السيطرة على إيفانوفكا وتفصيل خسائر الجيش الأوكرانيARانتقادات واسعة لجياني إنفانتينو بعد مقترح بيع حصص في كأس العالم وانقسام الاتحادات الكرويةARالحوثيون لـCNN: لا نحتاج لأوامر من طهران لتصعيد الصراع مع السعودية
Newsgather

npm

Estable7 noticias5 fuentesÚltima actualización: 9/7/2026

Últimas noticias

Malicious Bitwarden CLI Package Compromised npm for 93 Minutes
En desarrollo
Tecnología·24/4/2026Resumen IA

Malicious Bitwarden CLI Package Compromised npm for 93 Minutes

On April 22, 2026, a malicious version of Bitwarden's CLI was published to npm under the official @bitwarden/cli package name for 93 minutes. The backdoored package targeted infrastructure credentials including GitHub tokens, SSH keys, AWS/GCP/Azure credentials, and GitHub Actions secrets rather than Bitwarden vaults. Bitwarden removed the package and found no evidence of vault data access. Security researchers determined the attack exploited a compromised GitHub Action in Bitwarden's CI/CD pipeline, connected to the broader Checkmarx supply chain campaign.

C
CryptoSlate
4 min de lectura
Malicious Bitwarden CLI Package Exfiltrated Infrastructure Credentials via Compromised npm Release
En desarrollo
Tecnología·24/4/2026Resumen IA

Malicious Bitwarden CLI Package Exfiltrated Infrastructure Credentials via Compromised npm Release

On April 22, 2026, a malicious version of Bitwarden's command-line interface was published to npm under the official package name @bitwarden/[email protected], remaining available for 93 minutes. The compromised package targeted infrastructure credentials including GitHub tokens, npm tokens, SSH keys, AWS/GCP/Azure credentials, and GitHub Actions secrets. Security firm JFrog analyzed the payload and found it had no interest in Bitwarden vaults—only in credentials governing build, deployment, and infrastructure automation. Bitwarden confirmed the incident is connected to the broader Checkmarx supply chain campaign and found no evidence of end-user vault access or production system compromise.

C
CryptoSlate
4 min de lectura