TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
As AI coding tools accelerate software development, they also introduce open-source dependencies at a pace that can overwhelm security teams, leading to…
Cybersecurity researchers at Trend Micro's TrendAI have uncovered a set of 14 trojanized npm packages that masquerade as legitimate calendar and streak…
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
Security researchers at Cycode have disclosed a chain of vulnerabilities in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit.…
A newly disclosed zero-day vulnerability in GeoServer is being actively exploited in the wild, according to threat intelligence firm watchTowr. The flaw,…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack targeting users of Alibaba developer tools with a cross-platform remote access trojan…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…