North Korean Hackers Compromise Popular npm Packages to Target Developer Environments
North Korea–linked operators have quietly turned popular npm packages into a high‑volume access vector for developer and build environments, chaining multipl...
Aggregating 4676 articles from trusted cybersecurity sources
North Korea–linked operators have quietly turned popular npm packages into a high‑volume access vector for developer and build environments, chaining multipl...
GitLab has released security updates for both the Community Edition (CE) and Enterprise Edition (EE), addressing 13 vulnerabilities that could allow unauthor...
More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the maliciou...
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto...
The Node.js Project has released security updates for the active Node.
Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor net...
TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent JavaS...
Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global sec...
The U.S.
How do you protect your executives when truth doesn’t seem to be truth anymore? It’s a question BlackCloak Founder and CEO Dr.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is requ...
No articles found.