View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Flooding Dropper campaign spreads 846 malicious npm packages

๐Ÿšจ ACTIVE EXPLOITATION

  • Flooding Dropper campaign spreads 846 malicious npm packages UPDATE: A campaign has distributed 846 malicious npm packages delivering cross-platform malware.

    • The campaign targets developers and CI/CD environments on Windows, Linux, and macOS.
    • Packages act as loaders for second-stage malware that can steal data and establish persistence.
    • Install or import execution selects a platform payload, downloads it from hardcoded hosts, or reconstructs it through DNS TXT records.
    • Payloads launch as detached processes; Windows samples patch security interfaces and use Registry Run keys and scheduled tasks.
    • Package names commonly use terms such as "bigops" and "bnpl," with many releases in the 35.x.y version range. ๐Ÿ“„ Source: stepsecurity.io ยท ๐Ÿ“Ž Coverage: sonatype.com ยท ๐Ÿ‘ via The Hacker News
  • ClickFix Attacks Deliver macOS Stealer Capable of Draining Crypto Wallets UPDATE: ClickFix attacks are delivering a macOS stealer that drains cryptocurrency wallets.

    • macOS users are targeted, including cryptocurrency holders and users with saved credentials.
    • The Go-based stealer harvests browser passwords, Apple iCloud Keychain data, cached credentials, and cryptocurrency assets.
    • Victims paste a ClickFix command into Terminal, launching a Bash profiler that fetches a CPU-compatible Mach-O payload.
    • A DRAIN routine targets Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP wallets, while fake system-error prompts seek macOS credentials.
    • Payload staging and command-and-control infrastructure link to Aeza Group, a sanctioned Russian bulletproof hosting provider. ๐Ÿ“„ Source: huntress.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • UNC6671 Uses Vishing to Steal SaaS Data From Financial Firms UNC6671 is using vishing to steal SaaS data and extort organizations.

    • Financial services, private equity, law firms, and professional-services organizations are targeted.
    • Microsoft 365, Okta, and other SaaS data are stolen for extortion.
    • Attackers impersonate IT help desks and call employees on personal mobile phones about urgent passkey or MFA changes.
    • Spoofed login portals use AiTM phishing to capture credentials, MFA tokens, and session cookies.
    • Associated brands include BlackFile, Redact, Pink, Helix, and Falcon; domains include passkeyhelpdesk[.]com and passkeydeploy[.]com. ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Unlimited Technology Systems breach affects 3.8 million people UPDATE: Unlimited Technology Systems disclosed a breach affecting 3,803,750 people.

    • Unlimited Technology Systems provides practice management and revenue-cycle software to healthcare providers.
    • Patient data from the company's healthcare-provider clients was impacted, including 3,803,750 individuals.
    • Exposed data included names, contact details, Social Security numbers, diagnoses, insurance and claims information, and identity documents.
    • An unauthorized actor accessed a commercial data center and exfiltrated files between October 5 and October 10, 2025.
    • The incident was discovered on October 19, 2025; no threat actor or ransomware group has claimed responsibility. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via BleepingComputer
  • Ohio man pleads guilty to hacking court database and Connecticut company Michael Rogers pleaded guilty to hacking a Stark County court database and a Connecticut company.

    • The case affects Stark County's CJIS court-record system and a Connecticut-based multinational corporation.
    • Rogers accessed personal information from court systems serving Canton, Massillon, Alliance and Stark County.
    • He used a custom program to query and scrape CJIS data, collecting names and birth dates from nearly 300,000 people.
    • He used malware to obtain more than 150,000 employee names, corporate user IDs and passwords from the company.
    • Proxy servers rotated his IP address, and he later destroyed a phone, computer and hard drive containing evidence. ๐Ÿ“„ Source: storage.courtlistener.com ยท ๐Ÿ“Ž Coverage: cantonrep.com ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ”“ CVEs & KEV

  • CVE-2026-64637 โ€” CVSS 9.9 โ€” Improper privilege management in the XML-RPC API of Plesk before 18.0.80, all...
  • CVE-2026-71847 โ€” CVSS 8.7 โ€” Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buf...
  • CVE-2025-58375 โ€” CVSS 8.1 โ€” Frappe has potential SQL Injection due to missing validationFrappe is a full-...
  • CVE-2026-64636 โ€” CVSS 7.7 โ€” An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and ...
  • CVE-2026-44964 โ€” CVSS 6.5 โ€” The OnCallNotificationActivity in the Datadog Android application is declared...
  • CVE-2026-47364 โ€” CVSS 6.5 โ€” On every successful login, the Datadog Android application calls FirebaseCras...
  • CVE-2026-47361 โ€” CVSS 6.4 โ€” BubbleChatActivity in the Datadog Android application is declared android:exp...
  • CVE-2026-47363 โ€” CVSS 6.3 โ€” The launcher activity AppActivity in the Datadog Android application is decla...

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • tl;dv Firebase flaw exposed 181,874 meeting records and live call IDs UPDATE: A tl;dv Firebase misconfiguration exposed customers' meeting metadata and enabled potential access to live calls.

    • tl;dv customers included government agencies, universities, and major companies across 35,003 email domains.
    • The exposed Firestore meetings collection contained 181,874 records tied to 84,312 users.
    • Records revealed creator emails, Google Meet or Microsoft Teams conference IDs, providers, timestamps, and recording status.
    • Authenticated users could obtain a Firebase token through gw.tldv.io/v1/users/firebase/token and query the cross-tenant collection; about 1,000 meetings were reportedly recording at any time.
    • More than 1,000 of 27,334 sampled meetings were publicly accessible, exposing 715 invitee email addresses across 228 domains. ๐Ÿ“„ Source: bobdahacker.com ยท ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via r/netsec
  • Cyberattacks hit municipal water systems across at least seven U.S. states Hackers targeted municipal water and wastewater systems across at least seven U.S. states.

    • Municipal water and wastewater utilities in at least seven states were affected.
    • More than 30 Minnesota facilities and nine Michigan systems were targeted.
    • Attackers remotely accessed internet-facing control devices and changed IP addresses and administrator passwords.
    • Utilities lost monitoring and control capabilities, with some operations disrupted or shifted to manual mode. ๐Ÿ“„ Source: fbi.gov ยท ๐Ÿ“Ž Coverage: nbcnews.com ยท ๐Ÿ‘ via r/cybersecurity

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check