GitHub to Disable npm Install Scripts by Default to Combat Supply Chain Attacks
GitHub has announced significant security changes for npm version 12, set to release next month, aimed at mitigating software supply chain attacks.…
Latest cybersecurity news, breaches, vulnerability disclosures and industry developments.
GitHub has announced significant security changes for npm version 12, set to release next month, aimed at mitigating software supply chain attacks.…
Two security teams have demonstrated that OpenClaw, a popular self-hosted AI agent, can be tricked into executing attacker-controlled code or leaking sensitive…
Europol, in coordination with international law enforcement, has disrupted AudiA6, a cryptocurrency laundering service that facilitated the washing of over €336 million…
An INTERPOL-led operation codenamed Operation Ramz has successfully disrupted Sniper Dz, a decade-old phishing-as-a-service (PhaaS) platform, resulting in 201 arrests across 13…
Google has filed a lawsuit against a Chinese cybercrime network accused of using its Gemini AI agent to power a phishing-as-a-service (PhaaS)…
The U.S. government has ordered Anthropic to suspend access to its most advanced AI models, Claude Fable 5 and Mythos 5, for…
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way…
Employee onboarding often involves sharing temporary passwords via email or SMS, creating security risks if intercepted or never changed. Attackers exploit weak…
A recent industry study conducted by Spur Intelligence, surveying over 200 security practitioners, reveals that anonymizing infrastructure—including VPNs and residential proxy networks—now…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…