New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
Cybersecurity researchers from Elastic Security Labs have disclosed a new campaign that delivers the CastleStealer information stealer via a previously unreported malware…
Cybersecurity researchers from Elastic Security Labs have disclosed a new campaign that delivers the CastleStealer information stealer via a previously unreported malware…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…
Security firm AIR demonstrated a critical supply chain vulnerability in AI agent ecosystems by creating a fake skill named 'brand-landingpage' that bypassed…
Stitch is a design tool by Google (stitch.withgoogle.com) that was impersonated by AIR's fake skill to appear legitimate during security scans.
Google's AI Agent Development Kit (adk-samples) had a CI/CD vulnerability enabling attacker code execution and repository takeover via pull requests.
Cybersecurity researchers at Novee Security have identified a critical exploitable pattern in CI/CD workflows, codenamed Cordyceps, that allows unauthenticated attackers to hijack…
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months…
Google was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…