Researchers at Kaspersky Labs have uncovered a massive, firmware-level compromise affecting Android devices globally. Dubbed Keenadu, this...
supply chain attack
A new report from Unit 42 has exposed a highly targeted supply chain attack that turned one...
In a disturbing first for enterprise security, researchers at Koi Security have uncovered a malicious Microsoft Outlook...
The notorious North Korean hacking syndicate, Lazarus Group, has launched a new, highly sophisticated branch of its...
A sophisticated supply chain attack has struck the dYdX decentralized exchange protocol, injecting malicious code into official...
The notorious Chinese state-sponsored threat group Lotus Blossom has resurfaced with a dangerous new toolkit, compromising the...
A sophisticated supply chain attack has struck the open-source ecosystem, leveraging compromised developer credentials to inject malware...
The booming ecosystem of personal AI agents has hit its first major security speed bump. VirusTotal has...
The developer behind Notepad++, the ubiquitous open-source text editor found on millions of developer desktops, has confirmed...
Security researchers at Morphisec have uncovered a massive compromise affecting eScan, an enterprise antivirus solution developed by...
The viral popularity of AI coding assistants has attracted a new kind of predator. On January 27,...
In a clever twist on software supply chain attacks, threat actors are weaponizing a quirk in GitHub’s...
It looked like just another UI library. “ansi-universal-ui” promised to be a “lightweight, modular UI component system...
The perfect job offer landed in your inbox. The recruiter was polite, the company looked legitimate, and...
A compromised installer for EmEditor, a text editor trusted by developers worldwide, has been used to distribute...
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog with four...
A deceptive new supply chain attack has been uncovered in the Python ecosystem, where a malicious package...
A disturbing new tactic has emerged in the Linux software ecosystem, turning trusted developer accounts into vehicles...
Developers relying on orval to generate type-safe clients from OpenAPI specifications are being urged to update immediately...
The “Contagious Interview” campaign, a sophisticated cyber-espionage operation attributed to North Korean (DPRK) threat actors, has evolved...