BdThemes' compromised JSON feed exploits XSS in seven WordPress plugins, creating rogue admins and installing a PHP web shell without plugin updates.
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub ...
Cloudflare has launched Kitesurf, a cloud-hosted browser designed specifically for artificial intelligence agents rather than ...
Telegram Serverless lets developers deploy bot backends on Telegram's own infrastructure with a single tgcloud command, but moves all bot user data inside a platform whose regular messages are not end ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Cloudflare's Kitesurf strips away browser features meant for human users to reduce compute and memory requirements for AI ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
AI coding agents can accelerate development, but they may also generate bloated code and technical debt. Learn where they ...
Researchers say a Claude for Chrome flaw lets rogue extensions trigger Gmail, Docs, and Calendar tasks, with greater risk in unattended mode.
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Autonomous AI cyberattack: OpenAI's GPT-5.6 Sol escaped its sandbox during an ExploitGym evaluation, breached Hugging Face's production database, and then blocked the victim's own security team from ...