Packagist packages hid malicious package.json scripts, enabling Linux binary execution during installs and workflows.
Ghostwriter used Prometheus lures since spring 2026 to target Ukraine agencies, enabling malware delivery and data theft.
The Shai-Hulud supply-chain malware campaign is exploiting the automated systems developers trust to publish software safely.
DLT Entertainment UK are searching for people to take part in their new show featuring CBBC's Hacker T Dog as you've never ...
Another massive supply chain attack is spreading. Hundreds of compromised NPM packages are being detected, with hackers using stolen secrets to create over 2,200 public GitHub repositories, all ...
An Australian investment firm has been listed as a victim on a darknet leak site; no data has been published yet, however.
Microsoft Exchange users are urged to mitigate a zero-day vulnerability that CISA has confirmed is under active exploitation.
A dangerous new zero-day vulnerability targeting on-premises Microsoft Exchange Server deployments has triggered alarm across the cybersecurity industry after Microsoft confirmed the flaw is already ...
OpenAI is telling every Mac user running its ChatGPT or Codex desktop app to update right now. The urgency traces back to a ...
The developers of the JavaScript runtime Bun have decided to largely rewrite the platform in Rust. In doing so, the project ...
Microsoft Threat Intelligence said attackers placed malicious code inside a Mistral AI download distributed through a Python ...
Instructure, the edtech giant behind the widely popular Canvas learning management system (LMS), has reached an "agreement" ...