GitLab RCE PoC Exploit Allows Authenticated Users to Execute Commands as Git
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit for a remote code execution (RCE) vulnerability in self-managed…
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit for a remote code execution (RCE) vulnerability in self-managed…
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…
The cybersecurity landscape is witnessing a surge in vulnerability clearinghouse announcements, but according to this analysis, most will fail because they focus…
New research from Carnegie Mellon University PhD student Jacob Ginesin, also a cryptographic auditor at Cure53, reveals that GitHub's 'Verified' commit badge…
The Patch the Planet project aims to secure open-source projects through collaboration between OpenAI and Trail of Bits.
OpenAI has announced the release of an improved version of its GPT-5.5-Cyber model as part of the Daybreak initiative, aimed at helping…