A massive wave of “watering hole” attacks has turned thousands of legitimate WordPress websites into traps for...
malware
The developer behind Notepad++, the ubiquitous open-source text editor found on millions of developer desktops, has confirmed...
Security researchers at Morphisec have uncovered a massive compromise affecting eScan, an enterprise antivirus solution developed by...
In a clever twist on software supply chain attacks, threat actors are weaponizing a quirk in GitHub’s...
A sophisticated malware campaign is turning a standard security verification step into a trap. Security researchers at...
A compromised installer for EmEditor, a text editor trusted by developers worldwide, has been used to distribute...
Cyber spies aligned with North Korea are now weaponizing a tool beloved by developers worldwide—Visual Studio Code—to...
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog with four...
A critical privilege escalation vulnerability in the Android ecosystem is raising alarms after security researcher Canyie publicly...
A deceptive new supply chain attack has been uncovered in the Python ecosystem, where a malicious package...
A disturbing new tactic has emerged in the Linux software ecosystem, turning trusted developer accounts into vehicles...
A new wave of cyberattacks is targeting users looking for free software, turning their computers into unwilling...
The “Contagious Interview” campaign, a sophisticated cyber-espionage operation attributed to North Korean (DPRK) threat actors, has evolved...
The tools that software developers trust most are being turned against them in a sophisticated new malware...
A new and sophisticated campaign targeting enterprise environments has been uncovered by Socket’s Threat Research Team. Five...
The resilient “GlassWorm” threat actor, known for embedding malicious code into Visual Studio Code extensions, has returned...
In a revelation that exposes a gaping hole in the browser extension ecosystem, Koi Security has unmasked...
The Cardano community is currently in the crosshairs of a highly sophisticated “wolf in sheep’s clothing” campaign....
In a major supply chain security incident, the popular text editor EmEditor has confirmed that its official...
The Java ecosystem, long considered a fortress compared to the wild west of npm, has been breached...