In a sophisticated supply chain attack discovered by the StepSecurity threat intelligence team, a legitimate Japanese DeFi...
supply chain attack
The threat actor known as GlassWorm has significantly escalated its operations, pivoting from simple malicious listings to...
Cybersecurity investigators at Socket’s Threat Research Team have sounded the alarm after discovering a cluster of malicious...
The JavaScript development community is on high alert following a coordinated supply chain attack targeting two popular...
A severe security flaw has been identified in SandboxJS, a popular JavaScript sandboxing library used to safely...
In a sophisticated supply chain manipulation, the xygeni-action GitHub Action was recently targeted by a critical “tag...
The eSentire’s Threat Response Unit (TRU) recently uncovered a sophisticated campaign involving a Remote Access Trojan (RAT)...
The Gogs project, a popular self-hosted Git service prized for its simplicity and painless setup, has been...
Socket’s Threat Research Team has uncovered a sophisticated supply chain attack targeting PHP developers through Packagist, the...
Cybersecurity researchers at Ctrl-Alt-Intel have released a detailed investigation into a systematic campaign targeting the heart of...
Cybersecurity researchers at XLab have issued a major report detailing the re-emergence of Funnull (also known as...
Cybersecurity researchers at Socket have uncovered a sophisticated security breach affecting the popular Aqua Trivy VS Code...
Christopher Robinson, Chief Technology Officer and Chief Security Architect at the Open Source Security Foundation (OpenSSF), has...
Cybersecurity researchers at Socket have uncovered a sophisticated multi-stage malware operation, dubbed “StegaBin,” specifically designed to harvest...
Socket’s Threat Research Team recently uncovered a dangerous new supply chain attack: a malicious Go programming module...
Late last year, the cybersecurity community was put on high alert when the ReversingLabs research team uncovered...
Tenable Research has uncovered a highly sophisticated, malicious npm package that amassed approximately 50,000 downloads before its...
The job hunt just got a lot more dangerous for software engineers. Microsoft Defender Experts identified a...
Developers themselves are increasingly the primary target for cybercriminals, a new supply chain attack has been uncovered...
A highly active cybercriminal group is turning legitimate websites into traps, deploying a potent mix of fake...