A new investigation by The Socket Threat Research Team has uncovered a sophisticated spear-phishing operation that has...
supply chain attack
A sophisticated supply chain campaign targeting .NET developers working with cryptocurrency has been uncovered, revealing a network...
A malicious NuGet package masquerading as a popular .NET logging tool has been caught stealing cryptocurrency wallet...
A sophisticated malware campaign has been uncovered within the Visual Studio Code (VS Code) Marketplace, exposing a...
Security researchers recently uncovered a vulnerability in the open-source text and code editor Notepad++, allowing attackers in...
A popular bioinformatics tool became the latest lure in a software supply chain attack, as threat actors...
A seemingly innocent utility for Ethereum developers has been unmasked as a sophisticated stealth loader. The Socket...
In a significant reminder of the risks inherent to the digital supply chain, artificial intelligence giant OpenAI...
A sophisticated and unprecedented cyber campaign has struck the heart of South Korea’s financial infrastructure. In a...
Google’s Threat Intelligence Group (GTIG) has released a comprehensive analysis exposing a long-running and adaptive cyber-espionage campaign...
HelixGuard researchers have uncovered a malicious Python package uploaded to PyPI that impersonates the widely used “pyspellchecker”...
Salesforce has issued an urgent security alert after discovering unusual activity involving Gainsight-published applications connected to its...
The Socket Threat Research Team has uncovered a highly coordinated malware campaign operating across seven npm packages,...
In one of the largest open-source supply chain incidents ever recorded, Amazon Inspector security researchers have uncovered...
A sophisticated supply-chain attack has been uncovered in the NuGet package registry, where nine packages published under...
A sophisticated, self-propagating malware campaign known as GlassWorm has re-emerged, infecting three new VS Code extensions and...
Researchers at Datadog Security Research have uncovered a major supply-chain compromise in the npm ecosystem involving 17...
Koi Security has uncovered a massive supply-chain campaign dubbed PhantomRaven, which has silently infected the npm ecosystem...
Palo Alto Networks’ Unit 42 Threat Intelligence team has uncovered a sophisticated new malware family dubbed Airstalk,...
The Socket Threat Research Team has uncovered an extensive supply chain attack targeting the npm ecosystem, involving...