A supply-chain attack backdoored versions of Axios, a popular JavaScript library that's present in many different software ...
OpenAI revoked its macOS signing certificate after a malicious Axios dependency incident on March 31, 2026, preventing ...
A Vietnamese man has pleaded guilty in a Malaysian court to possessing protected wildlife parts without a license. Defense lawyer Mohamad Fazaly Ali Mohamad Ghazaly said Hoang Van Thai, 39, ...
North Korean hackers used an updated version of a known backdoor to target a popular npm package.
Meta has indefinitely paused work with $10B AI data startup Mercor after a LiteLLM supply chain attack exposed training ...
Google links Axios npm supply chain attack to UNC1069 after trojanized versions 1.14.1 and 0.30.4 spread WAVESHAPER.V2, ...
Socket and Endor Labs discovered a new TeamPCP campaign leading to the delivery of credential-stealing malware ...
TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ ...
FEATURE Two supply chain attacks in March infected open source tools with malware and used this access to steal secrets from ...
Uploads bring prompts and responses, but not project files, attachments, or AI-generated images. The rollout skips the UK, ...
Karpathy proposes something simpler and more loosely, messily elegant than the typical enterprise solution of a vector ...
A North Korea-nexus threat actor compromised the widely used axios npm package, delivering a cross-platform remote access ...