The HelixGuard Threat Intelligence Team has uncovered a widespread supply chain compromise affecting the Visual Studio Code...
supply chain attack
The official website of Xubuntu, a Linux distribution derived from Ubuntu, appears to have been compromised by...
Cybersecurity researchers at Koi Security have discovered the world’s first self-propagating malware targeting VS Code extensions on...
Cybersecurity researchers at Wiz Research have uncovered what they describe as a “pattern of secret leakage” affecting...
The Socket Threat Research Team has uncovered a growing trend among malicious package developers: leveraging Discord webhooks...
Researchers from Kandji’s Threat Intelligence team uncovered a malware campaign targeting macOS users through spoofed Homebrew installer...
The Socket Threat Research Team has sounded the alarm on an escalating wave of malicious npm activity...
The security of the open-source software supply chain was once again tested when JFrog’s security research team...
Microsoft Threat Intelligence has identified yet another variant of the XCSSET malware, a long-running macOS threat targeting...
Socket’s Threat Research Team has uncovered a supply chain attack involving two malicious Rust crates—faster_log and async_println—that...
Google Threat Intelligence Group (GTIG) and Mandiant Consulting have released new findings on BRICKSTORM, a backdoor malware...
The Python Package Index (PyPI) is once again the target of a phishing campaign aimed at maintainers,...
The Socket Threat Research Team has uncovered a new malware campaign hiding inside an npm package called...
Zscaler ThreatLabz has uncovered yet another supply chain attack against the Python Package Index (PyPI). In August...
In July 2024, cybersecurity firm CrowdStrike triggered a global-scale incident that left more than eight million PCs...
The malicious supply chain campaign dubbed “Shai-Hulud” has struck again, this time compromising multiple npm packages published...
The Socket Research Team has uncovered a large-scale supply chain attack on the npm ecosystem, with more...
Socket has detected a large-scale supply chain attack in progress targeting the npm ecosystem. The account of...
Researchers from ReversingLabs have discovered two malicious npm packages leveraging Ethereum smart contracts to conceal and deliver...
Renowned network services provider Cloudflare has also emerged as a victim in the recent Salesforce CRM attack,...