Hackers Compromise TanStack Query npm Package to Steal Developer Credentials
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates type-safe TanStack Query hooks. Ai...
20 articles
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates type-safe TanStack Query hooks. Ai...
A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path traversa...
A newly documented TerminalFix campaign is using fake Cloudflare CAPTCHA prompts to trick users into manually executing malicious PowerShell commands, ultima...
A Chinese-speaking threat actor tracked as TA4922 is deploying the PackClient remote access trojan via tax-themed phishing campaigns targeting organizations ...
Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent fram...
OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways...
A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermin...
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to...
ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform. These vulnerabilities could allow unauthenti...
A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in repor...
Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages by following instructions found in orga...
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations...
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code exec...
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen ...
A recent demonstration of prompt-injection research has revealed that Claude Code Opus 5, when running in its default Auto Mode, can be manipulated to execut...
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence, blockchain-hosted p...
Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record.
A Windows malware campaign disguised as a graduate-school resume has been observed delivering the SNOWLIGHT stager and a fileless VShell remote-access trojan...
A cache of leaked internal records has exposed what appears to be a structured Russian military cyber-operator pipeline embedded inside Bauman Moscow State T...
Dark Caracal-linked operators are using Ethereum smart contracts as a resilient fallback mechanism for a newly identified Go-based malware framework called G...