A massive supply chain attack on the Node Package Manager (npm) registry has infected over 400 packages with over 2 billion downloads with the ...
Typosquatting on popular AI services Paperclip and Browser Use, the malicious skills cracked skills.sh’s trending list, ...
Gemini CLI and Claude Code flaws let untrusted GitHub input reach CI workflows, including host command execution and API key ...
Maybe feeling left out from the questionable hype train of “Our AI models can’t be trusted”, Anthropic has released reports that their Claude model has “reached the ...
Malicious Solidity Pro VS Code extensions steal crypto wallets, API keys, SSH keys, and developer tokens, then exfiltrate the ...
AI agents crossed boundaries as cyberattacks hit critical systems, while tech giants shifted strategies and bet big on mobile ...
Las Vegas was hotter than hell last week, but not as hot as the market for artificial intelligence-enabled security at Black ...
The malicious npm packages are connected to a campaign that can affect computers running Windows, macOS, and Linux.
CrowdStrike's latest Threat Hunting Report traces a multiyear shift from conventional intrusions toward attacks that exploit trusted identities, cloud services, AI systems, and software dependencies.
Sandworm fake job malware WireGuard Ukraine: Russia's GRU ran a fake recruitment campaign targeting Ukrainian system administrators, hiding root-level malware inside a trojanized WireGuard VPN client ...