A severe security flaw has been identified in SandboxJS, a popular JavaScript sandboxing library used to safely...
supply chain attack
In a sophisticated supply chain manipulation, the xygeni-action GitHub Action was recently targeted by a critical “tag...
The eSentire’s Threat Response Unit (TRU) recently uncovered a sophisticated campaign involving a Remote Access Trojan (RAT)...
The Gogs project, a popular self-hosted Git service prized for its simplicity and painless setup, has been...
Socket’s Threat Research Team has uncovered a sophisticated supply chain attack targeting PHP developers through Packagist, the...
Cybersecurity researchers at Ctrl-Alt-Intel have released a detailed investigation into a systematic campaign targeting the heart of...
Cybersecurity researchers at XLab have issued a major report detailing the re-emergence of Funnull (also known as...
Cybersecurity researchers at Socket have uncovered a sophisticated security breach affecting the popular Aqua Trivy VS Code...
Christopher Robinson, Chief Technology Officer and Chief Security Architect at the Open Source Security Foundation (OpenSSF), has...
Cybersecurity researchers at Socket have uncovered a sophisticated multi-stage malware operation, dubbed “StegaBin,” specifically designed to harvest...
Socket’s Threat Research Team recently uncovered a dangerous new supply chain attack: a malicious Go programming module...
Late last year, the cybersecurity community was put on high alert when the ReversingLabs research team uncovered...
Tenable Research has uncovered a highly sophisticated, malicious npm package that amassed approximately 50,000 downloads before its...
The job hunt just got a lot more dangerous for software engineers. Microsoft Defender Experts identified a...
Developers themselves are increasingly the primary target for cybercriminals, a new supply chain attack has been uncovered...
A highly active cybercriminal group is turning legitimate websites into traps, deploying a potent mix of fake...
Researchers at Kaspersky Labs have uncovered a massive, firmware-level compromise affecting Android devices globally. Dubbed Keenadu, this...
A new report from Unit 42 has exposed a highly targeted supply chain attack that turned one...
In a disturbing first for enterprise security, researchers at Koi Security have uncovered a malicious Microsoft Outlook...
The notorious North Korean hacking syndicate, Lazarus Group, has launched a new, highly sophisticated branch of its...
A sophisticated supply chain attack has struck the dYdX decentralized exchange protocol, injecting malicious code into official...
The notorious Chinese state-sponsored threat group Lotus Blossom has resurfaced with a dangerous new toolkit, compromising the...