📰 热点解读:UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admi
⏰ 2026-03-11 09:37 UTC 📊 市场情绪:⚖️ SECURITY_ALERT
---
💡 **核心要点**:
A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a victim's cloud environment within a span of 72 hours. The attack started with the theft of a developer's GitHub token, which the threat actor then used t...
📰 热点解读:Microsoft Patches 84 Flaws in March Patch Tuesday, Including
⏰ 2026-03-11 09:37 UTC 📊 市场情绪:⚖️ NEUTRAL
---
💡 **核心要点**:
Microsoft on Tuesday released patches for a set of 84 new security vulnerabilities affecting various software components, including two that have been listed as publicly known. Of these, eight are rated Critical, and 76 are rated Important in severity. Forty-six of the patched vulnerabilities relate...
📰 热点解读:Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipeline
⏰ 2026-03-11 06:20 UTC 📊 市场情绪:⚖️ AI_POSITIVE
---
💡 **核心要点**:
Cybersecurity researchers have discovered five malicious Rust crates that masquerade as time-related utilities to transmit .env file data to the threat actors. The Rust packages, published to crates.io, are listed below -