Three malicious RubyGems packages in the SleeperGem attack skip CI runners, target developer machines, and install persistent ...
Stolen and leaked credentials lead to Node.js packages from AsyncAPI and Jscrambler Code Integrity being poisoned with ...
Malicious Jscrambler NPM package versions distributed a cross-platform credential stealer in a new supply chain attack.
JFrog finds 148 npm proxy packages turned student browsers into a DDoS botnet, while a mutable loader lets operators re-arm ...
Microsoft's July 2026 Patch Tuesday fixed 570 security vulnerabilities, pushing the monthly total past 620 and to a new ...
Learn how EvilTokens hides Microsoft 365 phishing behind browser-side decryption and how browser-level analysis helps SOC ...
A cybersecurity researcher poisoned an open weight AI model for under $100 in about an hour, exposing how easily these increasingly popular systems can be secretly compromised without detection.
The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm ...
GitHub Copilot security review launched in the desktop app July 14, giving all subscribers — Free tier included — AI-driven ...
Critical Zimbra flaw lets crafted emails run malicious code on opening. Users urged to patch to version 10.1.19 immediately.
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint ...