A new typosquatting campaign using the open-source package manager, NuGet, has been identified as potentially infecting Windows systems with malware. Packages employed in the campaign use MSBuild integration to run codes in a stealthy manner. Though this feature enhances the building and packaging process for software projects, it opens up a new vulnerability for script execution during a package’s installation. This is the first documented instance of threat actors exploiting this feature in NuGet packages.
Goldman Sachs Says Some Clients’ Data May Have Been Exposed in Law Firm Data Breach
Chris Dolmetsch and Bob Van Voris report: Goldman Sachs Group Inc. warned investors in some of its alternative investment funds that their data may have been


