Vite Frontend Build Tool Targeted by Malicious npm Packages
Vite, a popular JavaScript frontend build tool, was targeted by the ViteVenom campaign where malicious scoped npm packages impersonated the @vitejs/* namespace…
Cybersecurity products, tools, platforms and software categories.
Vite, a popular JavaScript frontend build tool, was targeted by the ViteVenom campaign where malicious scoped npm packages impersonated the @vitejs/* namespace…
ComfyUI is a web-based interface for AI image generation models. It is one of the AI services targeted by the NadMesh botnet…
Ollama is a tool for running large language models locally. It is targeted by NadMesh for credential harvesting.
Open WebUI is a web interface for interacting with AI models. It is targeted by NadMesh for credential theft.
Gradio is a Python library for creating web demos of machine learning models. It is targeted by NadMesh.
Jenkins is an open-source automation server. The SleeperGem malware checks for Jenkins environment variables to avoid running on CI runners.
Marimo is a reactive notebook for Python. CVE-2026-39987 is a pre-auth RCE vulnerability in Marimo notebooks before version 0.23.0.
Spring Cloud Gateway is an API gateway built on Spring WebFlux. CVE-2022-22947 affects it when the Actuator endpoint is exposed.
Apache Struts is a free, open-source MVC framework for creating Java web applications. CVE-2017-12611 is a Struts Freemarker tag flaw.
The Everfox Trusted Information Platform uses hardware-enforced separation to securely move mission-critical information across systems, classifications, and coalition partners, supporting rapid adoption…