A sophisticated software supply chain attack has compromised some of the most widely used npm packages … Critical npm Worm Infects AI Coding ToolsRead more
open source security
Why Most Critical CVEs Never Get Fixed Properly
Security teams have no shortage of vulnerabilities to investigate. Every day, new CVEs flood vulnerability management … Why Most Critical CVEs Never Get Fixed ProperlyRead more
204 Zero-Day Exploits Released as Exploitarium Sparks Open-Source Security Crisis
An anonymous GitHub researcher has released one of the largest public collections of unpatched software exploits … 204 Zero-Day Exploits Released as Exploitarium Sparks Open-Source Security CrisisRead more
Shai-Hulud Campaign Expands With 23 Malicious PyPI Packages
A new wave of the Shai-Hulud PyPI attack is accelerating concerns around open-source supply chain security. … Shai-Hulud Campaign Expands With 23 Malicious PyPI PackagesRead more
OWASP CVE Lite CLI Brings Developer-First Vulnerability Scanning to the Terminal
A new open-source tool is reshaping how developers approach application security. The OWASP CVE Lite CLI … OWASP CVE Lite CLI Brings Developer-First Vulnerability Scanning to the TerminalRead more
Malicious PyPI Package Exploits Typosquatting to Deploy Backdoor
A malicious PyPI package designed to mimic a widely used Python library has exposed thousands of … Malicious PyPI Package Exploits Typosquatting to Deploy BackdoorRead more
Massive npm Supply Chain Attack Targets Red Hat Packages
A large-scale npm supply chain attack has compromised dozens of official packages under the @redhat-cloud-services scope, … Massive npm Supply Chain Attack Targets Red Hat PackagesRead more
npm Resets Tokens After “Mini Shai-Hulud” Supply Chain Attack
A large-scale software supply chain attack has forced npm to take unprecedented action, resetting thousands of … npm Resets Tokens After “Mini Shai-Hulud” Supply Chain AttackRead more
“CypherLoc” Scareware Attack Targets Millions With Fake Alerts
A widely used AI development platform has been found vulnerable to a one-click account takeover, exposing … “CypherLoc” Scareware Attack Targets Millions With Fake AlertsRead more
Critical Dify AI Flaws Enable One-Click Account Takeover
A widely used AI development platform has been found vulnerable to a one-click account takeover, exposing … Critical Dify AI Flaws Enable One-Click Account TakeoverRead more