Collected every two hours from specialised publications — each link leads to the original article.
The subgroup of an Iranian nation-state group known asNemesis Kittenhas been attributed as behind a previously undocumented custom malware dubbed Drokbk that u…
Dropbox has revealed details of a phishing attack to which it fell victim. In the attack, a threat actor was able to steal code from the company after gatherin…
Earlier this month, GitHub suffered a massive security breach affecting numerous users’ accounts. The breach…GitHub Shares Details About The Stolen OAuth User …
A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new …
Rebuild with the latest golang in repos
The maintainers of the nx build system have alerted users to a supply chain attack that allowed attackers to publish malicious versions of the popular npm pack…
runc, as used in Docker and other products, allows AppArmor and SELinux restriction bypass, and thus a malicious Docker image could breach isolation.
The compromise of Nx Console shows how much infrastructure now sits behind a single developer account. GitHub repositories, CI/CD pipelines, container build sy…
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-l…
Update to 0.6.26, fixing several CVEs https://github.com/libexif/libexif/releases/tag/v0.6.26
Update to 0.6.26, fixing several CVEs https://github.com/libexif/libexif/releases/tag/v0.6.26
OpenAI revealed a GitHub Actions workflow used to sign its macOS apps led to the download of the malicious Axios library on March 31, but noted that no user da…
A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a victim's clo…
Cybersecurity researchers have disclosed details of a malicious Go module that's designed to harvest passwords, create persistent access via SSH, and deliver a…
In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In Au…
Cybersecurity researchers have alerted to a supply chain attack that has targeted popular npm packages via a phishing campaign designed to steal the project ma…
Cybersecurity researchers have alerted to a supply chain attack that has targeted popular npm packages via a phishing campaign designed to steal the project ma…
Cybersecurity researchers have alerted to a supply chain attack that has targeted popular npm packages via a phishing campaign designed to steal the project ma…
Cybersecurity researchers have flagged a supply chain attack targeting a Microsoft Visual Studio Code (VS Code) extension called Ethcode that has been installe…
An Android information stealing malware named FireScam has been found masquerading as a premium version of the Telegram messaging app to steal data and maintai…
A version of an open source ransomware toolkit calledCryptonitehas been observed in the wild with wiper capabilities due to its "weak architecture and programm…
private-cwd leaks access to the entire filesystem References: - https://bugs.mageia.org/show_bug.cgi?id=30007 - https://github.com/netblue30/firejail/issues/47…
ShinyHunters, a notorious cybercriminal underground group that's been on a data breach spree since last year, has been observed searching companies' GitHub rep…