China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach.
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Upwind identified a malicious release of [email protected] that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track ...
A trojanized QuickFox Windows installer delivered FDMTP in a supply chain attack active since at least August 2025, after ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
The seventh preview again brings a language extension for C#, improved compression APIs, and new features for Blazor.
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
Development environments have evolved into toolkits for directing coding models and coordinating agents. GitHub Copilot, ...