New 7-Zip Vulnerability CVE-2026-14266 Allows Code Execution via Crafted XZ Archives
A critical vulnerability in 7-Zip, identified as CVE-2026-14266, allows attackers to execute arbitrary code by tricking users into opening a specially crafted…
A critical vulnerability in 7-Zip, identified as CVE-2026-14266, allows attackers to execute arbitrary code by tricking users into opening a specially crafted…
A critical vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allows attackers to log in as any user by exploiting…
A new class of attack called Agent Data Injection (ADI) has been disclosed by researchers from Seoul National University, the University of…
A critical vulnerability in Cursor, an AI-powered code editor, allows arbitrary code execution on Windows when a user opens a cloned repository…
A remote script loader module found in the malicious npm packages, which fetches JavaScript from a GitHub repository through the jsDelivr CDN…
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service (DDoS) botnet for roughly…
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…
Datadog Security Labs has uncovered several overlapping campaigns that leverage dormant GitHub accounts—some created two to five years ago—to systematically enumerate corporate…
GitHub has officially released npm version 12, introducing significant security changes to reduce software supply chain risks. The most notable change is…
Researchers from Tel Aviv University, Technion, and Intuit have identified a novel attack vector called HalluSquatting that exploits AI coding assistants' tendency…