MemTensor npm, PyPI packages compromised with cross-platform credential stealer
A Go binary called sckit was added to four malicious releases, targeting developer secrets.
20 articles
A Go binary called sckit was added to four malicious releases, targeting developer secrets.
Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuard...
The U.S.
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication. The post SolarWinds Patches Critical RCE Flaws in...
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent by...
Australian PM Anthony Albanese criticized OpenAI’s response to the incident, which occurred in June 2026
New federal programs take years to launch and fund. State and local governments need cybersecurity software now.
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers. The post Astrana Health Data Breach Impa...
A highly severe vulnerability in Roundcube Webmail is being actively exploited, posing risks to unpatched email servers through unauthenticated SQL injection...
Varonis Threat Labs discovered AvisLoader, a Windows malware loader that uses the Tox peer-to-peer network for C2 and arrives through a malicious ClickFix lure.
Check Point has warned customers about the active exploitation of two critical vulnerabilities in its VPN gateway and Security Management products: CVE-2026-...
A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-...
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian gove...
North Korea-linked threat actor Konni has launched a targeted cyberespionage operation against Ukraine-focused entities using malicious Windows shortcut file...
Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy p...
ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new ...