Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Windsurf was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Security researchers at Wiz have identified a critical vulnerability pattern, dubbed GhostApproval, affecting six popular AI coding assistants. The flaw allows a…
Researchers from Tel Aviv University, Technion, and Intuit have identified a novel attack vector called HalluSquatting that exploits AI coding assistants' tendency…
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
Windsurf was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
A vulnerability in Windsurf allowed attacker-controlled content to rewrite local MCP config and register a malicious server, leading to command execution.