In a newly uncovered software supply chain attack, threat actors have successfully deployed a backdoored version of...
supply chain attack
Imperva researchers have uncovered a supply chain attack masquerading as a popular Python utility. The package in...
A deceptive and highly targeted phishing campaign has successfully compromised several popular npm packages, including eslint-config-prettier, eslint-plugin-prettier,...
In a revelation for the JavaScript ecosystem, Socket’s Threat Research Team has uncovered the widespread proliferation of...
A fraudulent extension for the Cursor AI IDE—an editor built upon Microsoft’s open-source Visual Studio Code—was used...
A new chapter in the ongoing Contagious Interview campaign has emerged, as the Socket Threat Research Team...
In a concerning development for WordPress site administrators, the Patchstack team has uncovered a targeted supply chain...
Researchers at ReversingLabs (RL) have uncovered a supply chain compromise of the popular ETHcode extension for Visual...
IBM X-Force has peeled back the layers on Microsoft Azure Arc, uncovering how the hybrid-cloud management tool—meant...
In a detailed expose, the Socket Threat Research Team has uncovered an ongoing and highly targeted supply...
A newly uncovered software supply chain campaign by the threat group Banana Squad has compromised more than...
In a concerning development for AI infrastructure security, XLab has uncovered an active exploitation campaign targeting ComfyUI—a...
In a sweeping campaign that blends social engineering with software subversion, a newly identified threat actor dubbed...
The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with its federal partners, has issued a high-priority...
A newly disclosed vulnerability in Insyde H2O UEFI firmware, tracked as CVE-2025-4275, allows attackers to bypass Secure...
SentinelLABS has unveiled an extensive report detailing a wave of cyber-espionage activity that directly targeted SentinelOne and...
The Socket Threat Research Team has disclosed two dangerous npm packages that masquerade as helpful developer tools—but...
Socket’s Threat Research Team has uncovered a targeted supply chain attack leveraging malicious RubyGems impersonating Fastlane plugins....
Socket Threat Research Team has uncovered a new threat lurking within the JavaScript ecosystem: four malicious npm...
In a recent revelation, Socket’s Threat Research Team has uncovered a stealthy npm supply chain attack leveraging...