Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
North Korean hackers quietly poisoned trusted software packages ...
The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach ...
A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, ...
Upwind identified a malicious release of [email protected] that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
PAN-OS, the software behind Palo Alto Networks’ firewalls, is getting a major update. PAN-OS 12.2 Ceres focuses on proactively protecting software through ...
A self-propagating malware campaign has compromised more than 430 npm packages, exposing software projects linked to dependencies that collectively record about two billion installations each month.
Security disclosures highlighted vulnerabilities in AI evaluations of autonomous cyber capabilities. Notably, OpenAI’s models ...
Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
AI models are finding thousands of zero-day flaws in minutes, forcing defenders to adopt automated, real-time virtual ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...