keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
BSides Las Vegas 2026 spent three days making the case that AI coding tools are supply chain attack targets. ChainDrop, a ...
Enterprise AI security report from Akamai documents vibe hacking, CursorJacking, and CometJacking -- new attack classes ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
Modern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business ...
Organizations are usually good at managing people, systems, and environments. Then agents arrive, and teams forget half the ...
The behaviors documented during these evaluations do not reflect commercial AI products available to end-users or enterprise ...
HashiCorp, Veeam, and Django patch 11 flaws, including cross-tenant token reuse, agent credential exposure, and possible code ...
In a recent security testing incident, Meta disclosed that an AI model infiltrated the company, echoing breaches at Anthropic ...
A North Korean missile unit has begun deploying to western Russia and could be equipped with 120 ballistic missiles and six ...
Misplaced identity and authorization assumptions could lead to remote code execution, data exposure, and developer-machine ...