Security researchers at Socket have uncovered a coordinated software supply chain campaign orchestrated through the GitHub account...
supply chain attack
In a high-impact escalation of software supply chain attacks, security researchers have identified a major compromise of...
Security researchers have uncovered a supply-chain attack on npm targeting developers who mistakenly install the unscoped tanstack...
Security researchers at Socket have identified a major expansion of the “Mini Shai-Hulud” supply chain campaign, which...
Researchers at ReversingLabs (RL) have uncovered a campaign dubbed PromptMink. Attributed to the North Korean-linked group Famous...
Security researchers at Iru have detailed a sophisticated new threat targeting macOS users through the software supply...
Security researchers at Yeeth Security have uncovered a sophisticated campaign on the Open VSX marketplace, where a...
Security researchers have sounded the alarm on a precision-targeted supply-chain compromise striking the SAP developer ecosystem. The...
Cybersecurity researchers at Panther Threat Research have released a detailed exposé on a massive, coordinated npm malware...
Checkmarx, a global leader in application security testing, has disclosed a significant breach of its internal systems....
Vimeo, the global video hosting giant, announced it has been swept up in a security incident involving...
The password management world was rocked this week as researchers from Socket revealed a major supply chain...
A new report from researchers at TrendMicro has exposed the evolution of Void Dokkaebi (also known as...
The cybersecurity world is facing a sprawling supply chain compromise as official distribution channels for Checkmarx, a...
The Python ecosystem is reeling from a sophisticated supply chain attack targeting Xinference (Xorbits Inference), a widely...
The global development community is on high alert following reports of a major security incident at Vercel,...
Security researchers from the OpenSourceMalware (OSM) team have uncovered a massive and rapidly expanding threat campaign targeting...
A new investigative report from Panther has identified a dangerous cluster of malicious packages lurking within the...
The esteemed open-source library @Axios recently fell victim to a sophisticated supply chain incursion in late March,...
Recently, a research contingent published a scholarly treatise detailing an exhaustive security audit of various API aggregators—commonly...