Posted inCybersecurity News
Emerging group, Water Curse, is weaponizing GitHub repositories and targeting cybersecurity professionals.
A newly identified threat actor, known as Water Curse, has launched a sophisticated supply chain attack targeting information security professionals, developers, red teamers, game developers, and DevOps teams. The campaign leverages weaponized GitHub repositories—at least 76 compromised accounts—to distribute advanced, multistage malware through seemingly legitimate open-source projects.