The popular Python package for monitoring data quality was briefly available as a malicious version. Provider Elementary ...
Anthropic fixed a significant vulnerability in Claude Code's handling of memories, but experts caution that memory files will ...
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via ...
An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive ...
A North Korean APT has crafted malicious software packages to appeal to AI coding agents, while ‘slopsquatting’ shows the ...
OX Security confirmed arbitrary command execution on six live platforms and estimates 200,000 MCP servers are exposed. Here's ...
A new supply chain attack targeting the Node Package Manager (npm) ecosystem is stealing developer credentials and attempting to spread through packages published from compromised accounts.
Academics from Singapore and China have found a way to make AI useful for cyber-defenders, by creating a technique that ...
Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of ...
Self-propagating npm worm steals tokens via postinstall hooks, impacting six packages and expanding supply chain attacks.
Developers of major Linux distributions have begun shipping patches to address a local privilege escalation (LPE) ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results