Threat actors have compromised four SAP npm packages with credential-stealing malware as part of the new mini...
supply-chain
The breach was claimed by the ShinyHunters extortion group, which threatened to leak the data by April...
The attack exploited a GitHub Actions script injection flaw, allowing the attacker to inject shell code that...
North Korean state-sponsored threat operation Void Dokkaebi, also known as Famous Chollima, has leveraged phony job interviews...
A new cluster of 73 extensions impersonating legitimate projects has been tied to the GlassWorm campaign.
TechCrunch reports that Vercel has disclosed that unencrypted customer information had been compromised prior to this month's...
Bitwarden CLI was reported by Socket and JFrog researchers to have been affected by the TeamPCP-linked supply...
HackRead reports that Anthropic has launched an investigation into the reported compromise of its Claude Mythos AI...
A self-propagating script was added to @automagik/genie and @pgserve packages.
Here’s why teams have to move to a more active security model.