A new Shai-Hulud supply-chain campaign, tracked as Trinitite, has compromised the npm package ...
Static application security testing, or SAST, is most useful when it is close to the way your team actually writes code. That is where Semgrep becomes valuable. It can scan source code quickly, fit ...
Alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive ...
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Claude Code Opus 5’s Auto Mode can be tricked into running malicious code via a simple website-summary request, succeeding in ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...