Skip to main content

Topic

Emerging Issue

Featured image for Axios npm package vulnerability incident blog post

Learn what happened with the Axios npm package vulnerability, how to confirm exposure to malicious versions, and how Tanium Guardian can help investigate.

Featured image for Claude Code source exposure blog post

Inside the npm packaging mistake that exposed half a million lines of Claude Code.

Featured image for CVE-2025-47813 Wing FTP Server vulnerability blog post

CISA KEV‑listed CVE‑2025‑47813 exposes Wing FTP Server install paths used in attack chains. Learn which versions are affected and how to remediate.

Desktop featured image: CTI blog 4 - wide

The Notepad++ update process was compromised by a supply chain attack, and users are strongly advised to upgrade to version 8.8.9 or later to ensure their security.

Tanium Guardian Spotlight - IDE Extensions

User-installable extensions for Visual Studio Code, Cursor, and other Integrated Development Environments are an increasingly exploited attack vector, with new malicious extensions discovered almost weekly. Do you have visibility and control?

Desktop featured image: CTI blog 1

SantaStealer spreads via Telegram and underground forums, the BlackForce phishing kit targets major brands, and Ink Dragon launches new attacks

Desktop featured image: CTI blog 2

Shanya PaaS spreads among ransomware groups, GrayBravo expands its footprint, and Storm-0249 exploits EDR processes to hide malicious activity

Desktop featured image: CTI blog 4 - wide

Hybrid 2FA phishing threatens enterprises, RomCom uses SocGholish to deploy Mythic Agent malware, and MuddyWater targets critical infrastructure with evolving tactics

Desktop featured image: CTI blog 3 - wide

Whisper Leak targets remote language models, @acitons/artifact targets GitHub Actions users, and Quantum Route Redirect simplifies phishing

Desktop featured image: CTI blog 1 - wide

Actors exploit RMM tools to target trucking and logistics companies, SesameOp uses the OpenAI Assistants API for C2 communications, and Google warns of rising adversary AI adoption in 2026

Desktop featured image: CTI blog 2 - wide

Learn about DragonForce expanding, Qilin rising as a global ransomware threat, and Water Saci spreading through WhatsApp.

Desktop featured image: CTI blog 4 - wide

Famous Chollima combines BeaverTail and OtterCookie, COLDRIVER deploys three new malware families, and Vidar Stealer 2.0 demonstrates upgraded capabilities