A national security emergency is quickly approaching due to the U.S.'s dependency on China's supply of medical-grade...
supply-chain
The trojanized package, which mimicked the popular Newtonsoft.Json library, published seven versions between August 13 and October...
The SleeperGem attack utilizes three malicious Ruby gems: git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab.
The ViteVenom campaign, attributed to the threat actor SuccessKey, builds upon the tactics seen in the earlier...
The jscrambler supply chain attack involved a malicious preinstall hook within version 8.14.0 of the npm package.
The incident occurred after a contributor's abusive behavior reportedly led to some members leaving the project.
The supply-chain attack was detected by application security companies Socket, Ox Security, and StepSecurity via version 1.20.21...
Socket says the campaign remains active and more attacks are likely.