A sophisticated supply chain attack has struck the open-source ecosystem, leveraging compromised developer credentials to inject malware...
supply chain attack
The booming ecosystem of personal AI agents has hit its first major security speed bump. VirusTotal has...
The developer behind Notepad++, the ubiquitous open-source text editor found on millions of developer desktops, has confirmed...
Security researchers at Morphisec have uncovered a massive compromise affecting eScan, an enterprise antivirus solution developed by...
The viral popularity of AI coding assistants has attracted a new kind of predator. On January 27,...
In a clever twist on software supply chain attacks, threat actors are weaponizing a quirk in GitHub’s...
It looked like just another UI library. “ansi-universal-ui” promised to be a “lightweight, modular UI component system...
The perfect job offer landed in your inbox. The recruiter was polite, the company looked legitimate, and...
A compromised installer for EmEditor, a text editor trusted by developers worldwide, has been used to distribute...
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog with four...
A deceptive new supply chain attack has been uncovered in the Python ecosystem, where a malicious package...
A disturbing new tactic has emerged in the Linux software ecosystem, turning trusted developer accounts into vehicles...
Developers relying on orval to generate type-safe clients from OpenAPI specifications are being urged to update immediately...
The “Contagious Interview” campaign, a sophisticated cyber-espionage operation attributed to North Korean (DPRK) threat actors, has evolved...
The tools that software developers trust most are being turned against them in a sophisticated new malware...
A seemingly minor misconfiguration in a regular expression could have allowed attackers to seize control of critical...
Security researchers at Sansec have discovered an active keylogger planted on the employee merchandise store of a...
A sophisticated threat actor, tentatively linked to China, is aggressively targeting critical infrastructure in North America with...
A routine utility often bundled with developer tools has been weaponized by cybercriminals to bypass security scanners...
A new, highly sophisticated malware framework has emerged from the shadows, specifically engineered to infest the modern...
The open-source ecosystem has once again been weaponized, this time targeting developers working with cryptocurrency libraries. In...
The resilient “GlassWorm” threat actor, known for embedding malicious code into Visual Studio Code extensions, has returned...