Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 ...
Open source software helps developers build applications faster, but every dependency can introduce security risks. In this ...
North Korean hackers quietly poisoned trusted software packages ...
Upwind identified a malicious release of keyv@6.0.0 that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach ...
The attackers behind the Atomic Arch supply chain campaign have adapted. After Arch Linux developers purged more than 1,900 compromised packages and declared the community repository clean in mid-June ...
V tomto vydání Postřehů se podíváme na AI model, který si sám nahrál malware na PyPI, na severokorejské útoky na npm balíčky, ...
AnySign4PC zero-day attack exploited mandatory South Korean banking software as a silent watering-hole weapon, letting ...
PAN-OS, the software behind Palo Alto Networks’ firewalls, is getting a major update. PAN-OS 12.2 Ceres focuses on proactively protecting software through ...
Amazon Threat Intelligence has tied a DPRK hacking group to four separate npm package supply chain attacks, including axios. The company’s security teams have connected the axios, debug, chalk, and ...
No Human Directed a Single Step. Roughly 17,000 Autonomous Actions Over One Weekend. One Named Zero-Day. Six of Seven ...