A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
Telegram Serverless lets developers deploy bot backends on Telegram's own infrastructure with a single tgcloud command, but moves all bot user data inside a platform whose regular messages are not end ...
A macOS ClickFix campaign uses more than 250 domains and server-side fingerprinting to hide AMOS lures from crawlers and ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
AI coding agents can accelerate development, but they may also generate bloated code and technical debt. Learn where they ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Researchers say a Claude for Chrome flaw lets rogue extensions trigger Gmail, Docs, and Calendar tasks, with greater risk in unattended mode.
Autonomous AI cyberattack: OpenAI's GPT-5.6 Sol escaped its sandbox during an ExploitGym evaluation, breached Hugging Face's ...