A convincing Microsoft lookalike tricks users into downloading malware that steals passwords, payments, and account access.
JFrog reports Telnyx PyPI package was poisoned with malware by TeamPCP Malicious update delivered hidden .wav payload that ...
A cyber attack hit LiteLLM, an open-source library used in many AI systems, carrying malicious code that stole credentials ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
A routine software update for Anthropic's Claude Code tool accidentally leaked its entire source code, sparking rapid ...
The IT security company NetKnights has released version 3.13 of its multi-factor authentication software, privacyIDEA ...
Although executed by different attackers – Axios by North Korean-linked goons, and Trivy et al. by a loosely knit band of ...
AMD adds Day 0 support for Google Gemma 4 across Radeon, Instinct, and Ryzen AI, enabling full-stack AI deployment.
Aqua Security’s Trivy vulnerability scanner compromise is trickling down ...
Anthropic has exposed Claude Code's source code, with a packaging error triggering a rapid chain reaction across GitHub and ...
Language package managers like pip, npm, and others pose a high risk during active supply chain attacks. However, OS updates ...
UNC1069 compromised Axios 1.14.1 and 0.30.4 via social engineering, impacting 100M weekly downloads and exposing supply ...