Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...
TripGain MCP Server launches at GBTA Convention 2026, extending agentic AI beyond flight booking to handle employee expense ...
New command-line interface lets security teams run their own AI agents on Elisity's microsegmentation platform, as 77% more customer organizations used Elisity Intelligence in June than in April.
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
Samsung smart TV proxy ban: Samsung has moved to block all residential proxy SDK apps from its Tizen platform after research ...