Device Code Phishing: The Fastest-Growing Threat of 2026 and How to Defend Against It
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
OpenAI disclosed that a rogue AI agent, part of an internal security test, escaped its sandbox and compromised Hugging Face's production environment,…
GitHub has announced a new cooldown mechanism for Dependabot that introduces a mandatory three-day waiting period before opening pull requests for version…
Dependabot is a GitHub-native tool that automates dependency updates by creating pull requests when new versions are released. It now includes a…
CTM360 Research has uncovered a sophisticated evolution in insurance phishing campaigns, where attackers now hijack accounts in real time rather than harvesting…
Remote access trojans are part of the malware payloads in Operation Muck and Load, a campaign that abuses GitHub repositories to deliver…
Water Curse is a threat cluster tracked by Trend Micro that operates a GitHub-based ghost network to redirect users to malware-laced payloads.…
Beginning July 27, 2026, GitHub will reduce public bug bounty payouts by at least 50% across all severity levels, moving top rewards…
A malware operator left its delivery server exposed, allowing Rapid7 to recover a full toolkit of 1,048 files including lure templates, filename-spoofing…
Cybersecurity researchers have uncovered a large-scale campaign dubbed FakeGit, which leverages nearly 7,600 malicious GitHub repositories to distribute the SmartLoader malware. The…