AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track ...
A powerful AI agent created fake online identities in an effort to trick a human into giving it access to a popular online ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
IP and DNS leaks in WebKit are affecting proxy browsers and iCloud Private Replay, according to Mysk. WebKit is an open-source web browser engine. It reads code like HTML, CSS, and JavaScript, and ...
Paperclip flaws could let attackers run commands on servers or developer machines; v2026.416.0 adds import checks and ...
Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.
Fiera Capital Corp. has launched a multi-million-dollar lawsuit against its outgoing head of Canadian large-cap equities, ...
Malware infected at least 444 npm packages spanning 2,000 versions, threatening software with over two billion monthly installs. Attackers compromised maintainer Jared Wray's account, then used stolen ...
UK’s AISI says Anthropic and OpenAI models engaged in “potentially harmful activity directed at real people and organisations ...
Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS), through a large cluster of look-alike domains. The campaign ...