Thirteen npm packages deliver WeaselBiscuit, a JavaScript stealer that harvests Chrome extension storage across Windows, macOS, and Linux.
Threat actors are exploiting CVE-2026-58138, a critical-severity remote code execution vulnerability in Orkes Conductor.
The research examines how building from source, enforcing provenance and applying layered security controls can significantly reduce exposure to open-source malware. What you'll discover Where malicio ...
The campaign allegedly involved an OpenAI agent swarm and abused package documentation systems, metadata fields, and registry ...
Trellix highlighted findings from its latest Trellix SecondSight Threat Hunting Report with implications for Indian organizations. Examining five critical campaigns observed between January and June ...
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, deploying different backdoors each.
DarkSword, JSCeal, Axios, Bitter APT, and APT28 campaigns reveal evolving tactics targeting iPhones, Southeast Asia, software ...
A swarm of internal OpenAI AI agents uploaded more than 2,000 malicious RubyGems packages in May 2026, exploiting RubyGems’ ...
A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused ...
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in ...
Chrome 153 Stable fixes 230 security issues, including an in-the-wild V8 out-of-bounds write that can run code inside the ...
Multiple espionage-motivated threat actors have rapidly adopted a newly discovered exploit kit that chains Chrome browser and ...