The SANS ISC Stormcast discusses Z-Shy Phishing, updates on Apple’s patching of zero-day vulnerabilities, details on the Fortinet exploit, and patches for Github and Apache Solr.

36 Malicious Strapi npm Packages Deliver Redis RCE, Persistent C2 Malware
A coordinated supply chain attack has been uncovered involving 36 malicious npm packages masquerading as Strapi CMS plugins, delivering a range of payloads including Redis


