keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
A malicious change was made to the legitimate QuickFox VPN installer, allowing it to secretly download a backdoor onto ...
Paperclip flaws could let attackers run commands on servers or developer machines; v2026.416.0 adds import checks and ...
Survey found more than two-thirds of respondents say their university does not take antisemitism seriously and does not ...
Malware infected at least 444 npm packages spanning 2,000 versions, threatening software with over two billion monthly installs. Attackers compromised maintainer Jared Wray's account, then used stolen ...
CrowdStrike has partnered with AWS to launch an interactive global competition designed to teach security professionals how ...
UK’s AISI says Anthropic and OpenAI models engaged in “potentially harmful activity directed at real people and organisations ...
Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS), through a large cluster of look-alike domains. The campaign ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results