keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach ...
Microsoft said compromised websites are retrieving malicious instructions from the BNB Chain blockchain before tricking ...
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals ...
A man will live the rest of his life behind bars for the murder of 27-year-old Wayne Pope in Suitland nearly 10 years ago.