Arch Linux AUR malware has forced an emergency adoption freeze after Wave Three of the Atomic Arch campaign deployed a ...
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Dolphin X is an AI-powered Windows stealer and RAT that targets 300+ apps, crypto wallets, SSH keys and cloud credentials ...
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious ...
State-sponsored hackers used compromised South Korean websites to exploit AnySign4PC and install SIGNBT or COPPERHEDGE ...
At Black Hat USA, Zenity Labs today announced new research detailing an active credential-stealing malicious skills campaign distributed through Vercel's skills.sh. The affected skill family amassed ...
SSH is a network tool used for remote, command-line login to systems that have the server enabled. It has sibling applications named SFTP and SCP that can be used to copy files. Microsoft Windows ...
A leaked n8n API key is only the start. GitGuardian's research traces the full chain, from exposed tokens and weak keys to ...
A flaw in Anthropic's Claude Cowork lets its AI agent break out of its virtual machine and reach sensitive files across a ...
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...