Researchers at ReversingLabs (RL) have uncovered a supply chain compromise of the popular ETHcode extension for Visual...
supply chain attack
IBM X-Force has peeled back the layers on Microsoft Azure Arc, uncovering how the hybrid-cloud management tool—meant...
In a detailed expose, the Socket Threat Research Team has uncovered an ongoing and highly targeted supply...
A newly uncovered software supply chain campaign by the threat group Banana Squad has compromised more than...
In a concerning development for AI infrastructure security, XLab has uncovered an active exploitation campaign targeting ComfyUI—a...
In a sweeping campaign that blends social engineering with software subversion, a newly identified threat actor dubbed...
The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with its federal partners, has issued a high-priority...
A newly disclosed vulnerability in Insyde H2O UEFI firmware, tracked as CVE-2025-4275, allows attackers to bypass Secure...
SentinelLABS has unveiled an extensive report detailing a wave of cyber-espionage activity that directly targeted SentinelOne and...
The Socket Threat Research Team has disclosed two dangerous npm packages that masquerade as helpful developer tools—but...
Socket’s Threat Research Team has uncovered a targeted supply chain attack leveraging malicious RubyGems impersonating Fastlane plugins....
Socket Threat Research Team has uncovered a new threat lurking within the JavaScript ecosystem: four malicious npm...
In a recent revelation, Socket’s Threat Research Team has uncovered a stealthy npm supply chain attack leveraging...
Socket’s Threat Research Team has uncovered a sophisticated supply chain attack on the Python Package Index (PyPI)...
Aidan Leon, cybersecurity practitioner and threat analyst at ZeroDay Labs, has disclosed a sophisticated supply chain attack...
A sophisticated ransomware campaign targeting National Defense Corporation (NDC) and its subsidiaries affected the defense supply chain,...
Malware authors have begun exploiting Google Calendar invites and Unicode Private Use Area (PUA) characters to deliver...
The ReversingLabs research team has uncovered yet another software supply chain attack targeting the cryptocurrency ecosystem, this...
rend Micro researchers have uncovered the full extent of an elaborate, multi-phase cyber-espionage operation attributed to Earth...
Aikido Security has uncovered a Remote Access Trojan (RAT) embedded in rand-user-agent, a JavaScript package downloaded ~45,000...