A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, ...
At TriMas, sustainability is an important part of how we operate, innovate and create long-term value," said Thomas Snyder, TriMas President and Chief Executive Officer. "We continue to strengthen our ...
Malicious npm packages impersonate Alibaba tools to deliver a cross-platform RAT with command execution, persistence, and ...
Compromising the open-source supply chain is easy to do and spreads more quickly than traditional supply-chain attacks, ...
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than ...
An unknown Chinese threat actor runs leaked DarkSword across 100-plus web properties, using fake AWS and Apple logins to ...
Open-source malware has changed shape. What once focused on noisy cryptomining has moved toward something far more valuable: access.
OpenAI is expanding access to its cyber AI models through approved partners, with added verification, monitoring, and human oversight.
A leaked n8n API key is only the start. GitGuardian's research traces the full chain, from exposed tokens and weak keys to ...
OpenAI on Monday announced a new purpose-trained cybersecurity model, GPT-5.6-Cyber, and restructured its Daybreak program into two access tiers — but the most significant part of the announcement was ...