Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk ...