MALFEX targets Windows developers via malicious npm packages delivering remote access tools, data stealers and hidden ...
GlassWorm hides malware in VS Code theme extensions, targeting developers through Visual Studio Marketplace and Open VSX.
China-nexus UAT-11587 targets Asian government and policy groups with Antino, a Rust backdoor that uses Microsoft 365 for C2.
CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices ...
Attackers exploited two PaperCut zero-day vulnerabilities to deploy AdaptixC2 malware and compromise an education organization’s ...
Tedious tasks in Illustrator and Photoshop can be automated in a variety of ways!Depending on the scale and difficulty of the ...
Software must be protected even after it has been distributed. This is because executable files, bytecode, and JavaScript ...
KryonOS is a small JavaScript-powered OS that turns a supported ESP32 development board with a touchscreen into a standalone computer with its own ...
Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, ...
npm, the package manager maintained by GitHub and shipped with Node.js, has released npm 12, shipping with a set of security related default changes to npm install alongside the deprecation of ...
On August 4, 2026, the Shai-Hulud npm worm returned for its sixth major campaign since September 2025 — and for the first time, it introduced three capabilities that no prior wave had shipped: ...