-
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a ne…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into broad credential and cryptocurrency-wallet stealers. Yeeth Security identified two publishers, helpe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A security researcher has revealed a critical design flaw in HP ThinPro versions 8 and 9, which allows attackers with physical access to a thin client’s storage drive to extract TPM-sealed LUKS disk-encryption keys. This vulnerability arises from…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through a single malicious link. According to Varonis Threat Labs, the vulnerability exploits Rovo&#…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A supply chain compromise affecting multiple BdThemes WordPress plugins has allowed attackers to hijack administrator sessions, create unauthorized admin accounts, and deploy persistent web shells, without modifying the plugin source code or requiring …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a domain controller before defenders intervene. During a March 2026 response engagement, Sophos Eme…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a privileged network attacker to write attacker-controlled files as root during node boot. This f…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware operations are increasingly targeting the people behind critical business processes, not just privileged IT administrators. Over a one-month observation period, ThreatLabz identified 351 victims across 334 organizations connected to a single…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic’s Claude Opus 5 has significantly reduced the likelihood of a successful indirect prompt injection (IPI) attack, bringing it down to 2% over 15 attempts in the Gray Swan IPI benchmark. This marks an improvement from a 5.5% success rate …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
North Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with local large language models. Retrieval-augmented generation, AI agents, and speech-to-text tooling …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


