NullReceiver lets two North Korea-linked npm packages decode a C2 IP from blank Ethereum transfers without smart contracts or ...
HashiCorp, Veeam, and Django patch 11 flaws, including cross-tenant token reuse, agent credential exposure, and possible code ...
Kali365 targets US organizations with attacker-controlled device codes, potentially exposing Microsoft 365 email, files, and ...
CISA adds three exploited Langflow, Tomcat, and N-central flaws to KEV, while Unit 42 links one campaign to a ...
GitGuardian found 321 n8n instances accepting leaked GitHub tokens that could expose workflows, data, and downstream ...
Researchers find more than six illegal AI access ads, including Poison Claude, which claims 5-15% pricing while its operator ...
Paperclip flaws could let attackers run commands on servers or developer machines; v2026.416.0 adds import checks and ...
CVE-2026-64531 lets local users exploit Open vSwitch kernel memory corruption to gain root, with a public PoC covering ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
Anthropic's Claude Mythos 5 spent 34 hours trying to backdoor an open-source project, then used a sockpuppet and rewrote Git ...
A trojanized QuickFox Windows installer delivered FDMTP in a supply chain attack active since at least August 2025, after ...
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results