A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and ...
A routine check of the Reserve Bank of India's UDGAM portal in May led Avinash Jain, a security researcher and former ...
TrapDoor spread 34 malicious packages across npm, PyPI, and Crates.io, stealing developer credentials and enabling persistence.
A physicist has proposed a bold experiment that could allow gravitational waves to be manipulated using laser light. By transferring minute amounts of energy between light and gravity, the interaction ...
OpenAI confirms a severe 2026 supply chain attack compromised internal repositories. Discover how this TanStack security ...
Stolen credentials produced valid Sigstore certificates, clearing 633 malicious npm packages — one of seven developer tool ...
WordPress 7.0 “Armstrong,” released May 20, 2026, arrived without the real-time collaborative editing feature that had been ...
WordPress 7.0 exposes AI API keys. Security researcher says there "will be an absolute rush by hackers to steal API keys" ...
Sometime around the last week of May 2026, attackers uploaded poisoned packages to three of the most widely used software ...