Multiple npm supply chain attacks used 50+ poisoned packages to spread IronWorm, a Rust-based stealer, and a Miasma worm ...
Packagist packages hid malicious package.json scripts, enabling Linux binary execution during installs and workflows.
Fake Claude Code installer malware used Google Ads to place spoofed AI tool pages above real documentation since March 2026.
SVG phishing email attacks are bypassing enterprise email security gateways by hiding JavaScript inside image files and ...
Perimeter Institute exploring interplay of quantum mechanical laws and information processing. The promise of quantum ...
A Bugcrowd researcher has unveiled ExploitBench, an independent benchmark of AI models for vulnerability exploitation ...
When OpenAI engineers discovered that a poisoned update to a widely used JavaScript library had executed on two corporate ...
Regulators face a tough balancing act as Canadians covet the controversial trades that have taken the U.S. by storm ...
Google’s Project Zero demonstrates a new zero-click exploit for the Pixel 10 phones, showing a full escalation from remote to kernel without user interaction. During the investigation Project Zero ...
Microsoft has identified an active supply chain attack targeting the npm package ecosystem. On May 28, 2026, a single threat actor operating under the newly created maintainer alias vpmdhaj (a39155771 ...
A new malware campaign has compromised nearly 2,000 WordPress websites by using Steam Community profile comments to hide ...