Mini Shai-Hulud Hits TanStack npm Packages
Mini Shai-Hulud compromises TanStack npm packages and spreads across PyPI
20 articles
Mini Shai-Hulud compromises TanStack npm packages and spreads across PyPI
Apple begins rolling out end-to-end encrypted RCS messaging between iPhone and Android in iOS 26.
Exploitation of open-source tools allows attackers to maintain persistent access after initial social engineering, warn ReliaQuest researchers
HiddenLayer reveals infostealer malware in a Hugging Face repository
The ICO has fined South Staffordshire Water nearly £1m for a series of data protection failings
ThreatFabric finds new TrickMo Android banking trojan variant routing C2 through The Open Network
Two new high-severity vulnerabilities, dubbed ’Dirty Frag’ when chained, have been found in the Linux kernel, affecting most Linux distributions
Ontinue uncovers fake Claude Code installer pushing PowerShell stealer abusing Chrome's IElevator2
Google Threat Intelligence Group details how cybercriminals attempted to launch a campaign based around an AI-developed Zero-Day targeting open-source software
The same extension applies to security updates shipped to US-based users of foreign-made drones
ShinyHunters has escalated its Canvas extortion campaign, defacing hundreds of school login pages and threatening to leak stolen data unless institutions neg...
ShinyHunters gets away with emails and other data on 200,000 Zara customers
Spanish police have arrested the suspected administrator of German dark web marketplace Crimenetwork
ACSC warns over a campaign targeting organizations which uses ClickFix to deliver Vidar infostealer malware
SentinelOne believes the PCPJack campaign may be the brainchild of a former TeamPCP member
Oasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijack
Commercial AI models were used to help plan and conduct cyber-attack against operational technology of a water and drainage facility, say researchers
Sophos finds fake Claude site spreading DonutLoader and a new Beagle backdoor via DLL sideloading
A China-linked threat actor backdoored a version of Daemon Tools to infect thousands
Traditional network security tools are undermining data protection, with Forrester and Capital One Software research warning AI adoption is impossible withou...