A sophisticated threat actor, tentatively linked to China, is aggressively targeting critical infrastructure in North America with...
supply chain attack
A routine utility often bundled with developer tools has been weaponized by cybercriminals to bypass security scanners...
A new, highly sophisticated malware framework has emerged from the shadows, specifically engineered to infest the modern...
The open-source ecosystem has once again been weaponized, this time targeting developers working with cryptocurrency libraries. In...
The resilient “GlassWorm” threat actor, known for embedding malicious code into Visual Studio Code extensions, has returned...
The Cardano community is currently in the crosshairs of a highly sophisticated “wolf in sheep’s clothing” campaign....
In a major supply chain security incident, the popular text editor EmEditor has confirmed that its official...
The well-known cryptocurrency wallet extension Trust Wallet appears to have recently fallen victim to a supply-chain attack....
The Java ecosystem, long considered a fortress compared to the wild west of npm, has been breached...
A new investigation by Koi Security has exposed a highly sophisticated supply chain attack lurking in the...
A new investigation by The Socket Threat Research Team has uncovered a sophisticated spear-phishing operation that has...
A sophisticated supply chain campaign targeting .NET developers working with cryptocurrency has been uncovered, revealing a network...
A malicious NuGet package masquerading as a popular .NET logging tool has been caught stealing cryptocurrency wallet...
A sophisticated malware campaign has been uncovered within the Visual Studio Code (VS Code) Marketplace, exposing a...
Security researchers recently uncovered a vulnerability in the open-source text and code editor Notepad++, allowing attackers in...
A popular bioinformatics tool became the latest lure in a software supply chain attack, as threat actors...
A seemingly innocent utility for Ethereum developers has been unmasked as a sophisticated stealth loader. The Socket...
In a significant reminder of the risks inherent to the digital supply chain, artificial intelligence giant OpenAI...
A sophisticated and unprecedented cyber campaign has struck the heart of South Korea’s financial infrastructure. In a...
Google’s Threat Intelligence Group (GTIG) has released a comprehensive analysis exposing a long-running and adaptive cyber-espionage campaign...
HelixGuard researchers have uncovered a malicious Python package uploaded to PyPI that impersonates the widely used “pyspellchecker”...
Salesforce has issued an urgent security alert after discovering unusual activity involving Gainsight-published applications connected to its...