PhantomEnigma uses more than 20 hijacked Brazilian government sites and compromised mailboxes to deliver a modular Node.js ...
Zimbra fixes a critical stored XSS flaw in its Classic Web Client that could let crafted emails run malicious scripts when ...
Stolen and leaked credentials lead to Node.js packages from AsyncAPI and Jscrambler Code Integrity being poisoned with ...
Malicious Jscrambler NPM package versions distributed a cross-platform credential stealer in a new supply chain attack.
Learn how EvilTokens hides Microsoft 365 phishing behind browser-side decryption and how browser-level analysis helps SOC ...
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint ...
The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.
JavaScript engineering teams have a shrinking window to prepare: npm v12, the package manager's most significant security redesign in its 16-year history, is expected to reach final release before the ...
Microsoft's July 2026 Patch Tuesday fixed 570 security vulnerabilities, pushing the monthly total past 620 and to a new ...
ServiceNow CVE-2026-6875, a critical unauthenticated RCE in the AI Platform, is under active exploitation. Threat ...
Owen Flowers and Thalha Jubair were convicted for their roles in the attack, which led to large costs for Transport for ...
Axios, one of the most popular JavaScript libraries, may be compromised and involved in a crypto wallet attack. The npm package attack is becoming more common, directly attacking projects, developers, ...