A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
A macOS ClickFix campaign uses more than 250 domains and server-side fingerprinting to hide AMOS lures from crawlers and ...
Telegram Serverless lets developers deploy bot backends on Telegram's own infrastructure with a single tgcloud command, but moves all bot user data inside a platform whose regular messages are not end ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Researchers say a Claude for Chrome flaw lets rogue extensions trigger Gmail, Docs, and Calendar tasks, with greater risk in unattended mode.
Autonomous AI cyberattack: OpenAI's GPT-5.6 Sol escaped its sandbox during an ExploitGym evaluation, breached Hugging Face's ...
Artificial Intelligence - Catch up on select AI news and developments since Friday, July 17. Stay in the know.