GuardingPearSoftware

@guardingpearsoftware
60 Followers
18 Following
2.7K Posts
| Building Unity Tools
| Cybersecurity + Gaming News
| Keeping your game safe from cheaters and hackers
👉https://assetstore.unity.com/publishers/27954
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm

Multiple official @redhat-cloud-services npm packages were compromised with a credential-stealing worm derived from the open-sourced Mini Shai-Hulud malware, targeting cloud credentials, and developer tooling across CI/CD pipelines.

Red Hat’s npm repository has been hit by a supply chain attack in which hackers published 32 malicious package versions to steal credentials and secrets from developer machines and deliver a self-propagating worm.
This incident is the latest in a string of supply chain attacks targeting open-source systems in recent months.
Security advisory: Brute force attack on Dashlane user accounts

Published June 1, 2026OverviewStarting on Sunday, May 31, 2026, an external party launched a brute force attack against certain Dashlane user accounts. The goal of the attack was to brute-force two...

Dashlane
Dashlane password manager has reported that a large-scale brute-force attack targeted user accounts on May 31, 2026. An unknown attacker tried to bypass two-factor authentication (2FA) by repeatedly guessing authentication codes in order to register unauthorized devices on users’ accounts. The attackers succeeded in downloading encrypted vault data from fewer than 20 users.

The GuardingPearSoftware Dashboard is finally live 🚀

Manage all your assets in one place, get direct access to beta releases, and try new features before they reach the Asset Store.

Go here👇
https://dashboard.guardingpearsoftware.com

Microsoft Security Response Center (@msftsecresponse) on X

Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile. We deeply value the security community,

X (formerly Twitter)
Microsoft has softened its position, easing concerns about possible legal action against researchers and reaffirming its support for coordinated vulnerability disclosure.
This comes after facing criticism from the security research community following the controversy involving Nightmare Eclipse, a researcher who publicly released functional proof-of-concept exploits for six Windows vulnerabilities. Three of those vulnerabilities were later exploited in real-world attacks.