The use of proxies by hostile states to carry out attacks in the UK is a "growing concern", the prime minister has said. Sir ...
The Bitwarden CLI NPM package compromise is tied to a Checkmarx supply chain attack and references the Shai-Hulud worm.
A ClickFix campaign targeting macOS users delivers an AppleScript-based infostealer that collects credentials and live ...
The supply chain attack on third-party library Axios has forced OpenAI to revoke its code-signing certificate and require ...
As supply-chain attacks against widely-used, open-source software repositories continue, experts are urging developers to not ...
A new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 "sleeper" extensions that turn malicious ...
The Bitwarden CLI was briefly compromised after attackers uploaded a malicious @bitwarden/cli package to npm containing a credential-stealing payload capable of spreading to other projects.
GlassWorm, a known malware, has put 73 harmful extensions into OpenVSX's registry. Hackers use it to steal developers' crypto ...
Two phishing campaigns, each using a different stealthy infection technique, are targeting organizations in attacks which aim ...
UNC6692 relies on email bombing and social engineering to infect victims with Snow malware: Snowbelt, Snowglaze, and ...
Dan Manges' new Columbus startup, which makes a key part of the environment in which software is built, has found its first ...