Since Sonatype began tracking malicious open source packages in 2017, we have logged nearly 2 million malicious packages.
CVE-2026-61500 is a critical authentication bypass in Rejetto HTTP File Server, discovered by Anthropic Mythos AI and exploited within 24 hours of public disclosure by a China-linked actor targeting ...
WordPress released version 7.1.3 on October 6, 2026, addressing vulnerabilities involving cross-site scripting, SQL injection ...
SC WordPress malware rebuilds its backdoor from files, the database, and shared memory; fewer than 20 wpForo exploit attempts ...
Spread the loveWhen you’re diving into the world of development, automation can save you a ton of time and headaches. GitHub ...
Courts must wrestle with question of whether AI creators should be held responsible for damage caused by rogue agents ...
OpenAI has admitted that one of its AI models accessed additional non-public Australian government data, just days after Prime Minister Anthony Albanese lashed the company for taking weeks to disclose ...
Discover how the TikTok WordPress Toolkit could enable hackers to steal AWS, SMTP, and API credentials, posing serious security risks to users.
A Group-IB researcher has found the Telegram account linked to the unauthorized ASOS customer notification previously engaged ...
A new open-source, browser-based software suite called KUREAS brings professional-grade probabilistic risk assessment to any ...
A modern website should do more than look good. It should load quickly, stay available, protect important data and conti ...
A VPS provides a more predictable share of CPU, RAM and storage resources, which can reduce server-side delays and help ...