Mini Shai-Hulud Attack Forces npm to Reset Bypass-2FA Publishing Tokens
The npm registry made an urgent platform-wide move last week after supply chain attacks threatened thousands of develope...
Found 414 results
The npm registry made an urgent platform-wide move last week after supply chain attacks threatened thousands of develope...
Google has publicly released proof-of-concept (PoC) exploit code for a critical, still-unpatched vulnerability in the Ch...
Hackers have found a new and alarming way to weaponize one of the most trusted platforms in the AI world. A threat actor...
A newly uncovered Android malware campaign has been quietly draining money from mobile users across four countries by si...
A widely-used JavaScript templating library called art-template has been weaponized to deliver a sophisticated iOS brows...
New TrapDoor supply chain campaign, an active attack deploying 34 malicious packages and over 384 related versions acros...
A newly identified scareware kit called CypherLoc is locking victims’ browsers and tricking them into calling fake Micro...
A newly disclosed zero-day vulnerability in the KnowledgeDeliver Learning Management System (LMS) has been actively expl...
A critical SQL injection flaw in Ghost CMS has been weaponized by at least two threat actor groups to silently poison ov...
A set of high-severity vulnerabilities has been identified in the Angular Language Service Visual Studio Code extension...
WordPress 5.2.4 released for public use from today, WordPress is the most popular content management system used by seve...
A new wave of a sophisticated mobile-aware phishing campaign uncovered in wide that mainly targeting non-governmental or...