Malicious npm Packages Disguised as PostCSS Tools Deploy Windows RAT
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…
Used by Rapid7 to publish indicators of compromise (IOCs) for the campaign.
GitHub has announced a critical security update to its official actions/checkout action, effective June 18, 2026, designed to block common pwn request…
GitHub was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Security firm AIR demonstrated a critical supply chain vulnerability in AI agent ecosystems by creating a fake skill named 'brand-landingpage' that bypassed…
Cybersecurity researchers at Novee Security have identified a critical exploitable pattern in CI/CD workflows, codenamed Cordyceps, that allows unauthenticated attackers to hijack…