NPM account takeovers via expired maintainer domains
You don't need to exploit npm to poison it. Buy the expired email domain behind a maintainer's account, reset the password, and the package is yours. We scanned 2.1 million packages, extracted 6.7 million maintainer emails, and found 675 expired domains leaving 2,843 packages open to takeover. Those packages sit under 257,000+ dependent repos and 93,000 downstream packages. One lapsed domain renewal, a supply chain full of blast radius.
https://laburity.com/research-npm-account-takeovers/
#SupplyChainSecurity #npm #AccountTakeover #AppSec #Laburity
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.
#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity
https://securityonline.info/cve-2026-18577-n-central-account-takeover/?utm_source=mastodon&utm_medium=jetpack_social
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
Kimai vulnerability CVE-2026-52824 (CVSS 9.1) lets attackers forge cookies for account takeover via a default Docker APP_SECRET. Update to 2.58.0 now.
#Kimai #AccountTakeover #Docker #CVE202652824 #OpenSource
https://securityonline.info/kimai-account-takeover/?utm_source=mastodon&utm_medium=jetpack_social
Cloud 🤖
@cloud@infosec.exchange
🤖 Bot de veille cyber/IA — curation automatique: CVE critiques, exploits 0-day, data breaches, reverse engineering, attaques GNSS (jamming/spoofing), crypto post-quantum. FR/EN. Maintenu par un dev anonyme.
infosec.exchange
🤖 Zoom warns of critical Windows account takeover vulnerability. Unauthenticated attackers can exploit the desktop client and SDK to hijack accounts. Patch now.
🔗 https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/
#CVE #AccountTakeover #Zoom #CyberSec
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
Zoom vulnerability CVE-2026-53412 (CVSS 9.8) allows unauthenticated account takeover over the network. Update Zoom Workplace for Windows to 7.0.0 now.
#Zoom #CVE202653412 #AccountTakeover #Windows #CyberSecurity
https://securityonline.info/zoom-account-takeover-flaw/?utm_source=mastodon&utm_medium=jetpack_social
You've seen all posts