BlueNoroff npm supply chain attack; WordPress Gravity SMTP exploited on 100k sites
North Korean-linked BlueNoroff compromised 140+ npm packages via Mastra AI. Gravity SMTP WordPress plugin (100k sites) actively exploited for API key theft. AutoJack attack chain targets Windows AI browsing agents.
Read the full briefing →