A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated ...
Stolen credentials produced valid Sigstore certificates, clearing 633 malicious npm packages — one of seven developer tool ...
Intel Xeon 6+ Clearwater Forest enters production with 288 cores, 18A process technology, massive cache, and major efficiency ...
Nvidia. This week the AI chipmaker — sorry, AI factory maker — reported a quarter that once again crushed forecasts, even if ...
The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker.
Showboat targets Linux telecom systems since mid-2022, enabling C2 access, proxying, and file theft across multiple countries ...
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has ...
A fresh Mini Shai-Hulud supply chain attack has hit over 320 NPM packages, along with GitHub Actions and a VS Code extension.
On May 19, the Mini Shai-Hulud worm compromised one npm maintainer account and pushed 639 malicious versions across 323 ...
Another massive supply chain attack is spreading. Hundreds of compromised NPM packages are being detected, with hackers using stolen secrets to create over 2,200 public GitHub repositories, all ...
Attackers performed an email takeover attack on a dormant maintainer account and published new node-ipc versions containing ...