Rust Supply Chain Attack: Malicious Crates with 245M Downloads Target Build-Time Execution
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
Cybersecurity researchers at Wiz have disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository. The flaw, present in the…
A now-patched vulnerability in Azure Cosmos DB could have allowed an attacker to escape the service's Gremlin query sandbox and gain full…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
The article discusses how AI models like Anthropic's Mythos are compressing exploit timelines, forcing a reevaluation of vulnerability management strategies. It argues…
Wiz analyzed the stage-2 implant used in the Rust supply chain attack, noting its persistence mechanisms and credential theft capabilities. They also…
Security researchers at Wiz have identified a critical vulnerability pattern, dubbed GhostApproval, affecting six popular AI coding assistants. The flaw allows a…