The perfect job offer landed in your inbox. The recruiter was polite, the company looked legitimate, and...
supply chain attack
A compromised installer for EmEditor, a text editor trusted by developers worldwide, has been used to distribute...
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog with four...
A deceptive new supply chain attack has been uncovered in the Python ecosystem, where a malicious package...
A disturbing new tactic has emerged in the Linux software ecosystem, turning trusted developer accounts into vehicles...
Developers relying on orval to generate type-safe clients from OpenAPI specifications are being urged to update immediately...
The “Contagious Interview” campaign, a sophisticated cyber-espionage operation attributed to North Korean (DPRK) threat actors, has evolved...
The tools that software developers trust most are being turned against them in a sophisticated new malware...
A seemingly minor misconfiguration in a regular expression could have allowed attackers to seize control of critical...
Security researchers at Sansec have discovered an active keylogger planted on the employee merchandise store of a...
A sophisticated threat actor, tentatively linked to China, is aggressively targeting critical infrastructure in North America with...
A routine utility often bundled with developer tools has been weaponized by cybercriminals to bypass security scanners...
A new, highly sophisticated malware framework has emerged from the shadows, specifically engineered to infest the modern...
The open-source ecosystem has once again been weaponized, this time targeting developers working with cryptocurrency libraries. In...
The resilient “GlassWorm” threat actor, known for embedding malicious code into Visual Studio Code extensions, has returned...
The Cardano community is currently in the crosshairs of a highly sophisticated “wolf in sheep’s clothing” campaign....
In a major supply chain security incident, the popular text editor EmEditor has confirmed that its official...
The well-known cryptocurrency wallet extension Trust Wallet appears to have recently fallen victim to a supply-chain attack....
The Java ecosystem, long considered a fortress compared to the wild west of npm, has been breached...
A new investigation by Koi Security has exposed a highly sophisticated supply chain attack lurking in the...