A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could ...
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...
Upwind identified a malicious release of keyv@6.0.0 that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
Compromising the open-source supply chain is easy to do and spreads more quickly than traditional supply-chain attacks, ...
Twelve datasets and evaluation systems, built by hand from thousands of real-world security flaws, give model builders and ...
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks ...
A leaked n8n API key is only the start. GitGuardian's research traces the full chain, from exposed tokens and weak keys to ...
New York, USA, August 4th, 2026, FinanceWireOpen-source software has long been built on trust. Developers routinely install ...
DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the ...
An unknown Chinese threat actor runs leaked DarkSword across 100-plus web properties, using fake AWS and Apple logins to ...