Artificial intelligence now shapes the landscape of modern software development. However, this rapid automation introduces significant security...
Software Supply Chain
A dangerous new vulnerability pattern threatens modern software developers. Specifically, researchers recently exposed the SymJack AI attack...
A significant vulnerability has been discovered in xmldom, a massive JavaScript library with over 23.5 million weekly...
The Open Source Security Foundation (OpenSSF), together with several prominent open-source and software foundations, has issued a...
The backdoor vulnerability in XZ-Utils first came to light in March 2024, and had it not been...
In a recently expose, Sonatype reveals a covert cyberespionage campaign orchestrated by the North Korea-linked Lazarus Group,...
A newly uncovered software supply chain campaign by the threat group Banana Squad has compromised more than...
A newly disclosed vulnerability tracked as CVE-2025-36852 has shaken the foundation of modern CI/CD systems and supply...
The Sysdig Threat Research Team (TRT) has uncovered a malicious campaign exploiting a misconfigured Open WebUI instanceβan...
Hunted Labs has uncovered that a widely used open source libraryβeasyjsonβis maintained and controlled by developers associated...
In an open letter, Patrick Opet, Chief Information Security Officer (CISO) at JPMorgan Chase, raises a critical...
The Socket Threat Research Team has exposed three malicious open-source packages masquerading as developer tools β designed...