Attackers stole a long-lived npm token from the lead axios maintainer and published two poisoned versions that drop a ...
TeamPCP hackers compromised the Telnyx package on the Python Package Index today, uploading malicious versions that deliver ...
With almost 175,000 npm projects listing the library as a dependency, the attack had a huge cascade effect and shows how ...
Socket and Endor Labs discovered a new TeamPCP campaign leading to the delivery of credential-stealing malware ...
Malicious LiteLLM 1.82.7–1.82.8 via Trivy compromise deploys backdoor and steals credentials, enabling Kubernetes-wide ...
An N-day vulnerability in Microsoft Word exposes nearly 14 million assets. Attackers can exploit this flaw to bypass security ...
Your phone is more capable than Android lets on.
Tenstorrent and Nvidia deliver new solutions for local AI models ...
Indirect prompt injection represents a more insidious threat: malicious instructions embedded in content the LLM retrieves ...
A new report from StepSecurity has uncovered a serious supply chain attack involving Axios, one of the most widely used HTTP ...
The U.S. Treasury Department on Thursday sanctioned six individuals and two companies accused of aiding North Korea in ...
The compromised packages, linked to the Trivy breach, executed a three‑stage payload targeting AWS, GCP, Azure, Kubernetes ...