GitHub Updates actions/checkout to Block Common Pwn Request Attack PatternsThe Hacker News·Jun 23, 14:22 UTC · Jun 23, 2026Vulnerability42
Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RATThe Hacker News·Jun 23, 09:01 UTC · Jun 23, 2026Malware42
Open-source CI/CD abuse detector guards against stolen credential attacksHelp Net Security·Jun 15, 00:00 UTC · Jun 15, 2026Vulnerability42
Microsoft Hacked to Deliver Malware to Claude and Gemini Users404 Media·Jun 9, 12:38 UTC · Jun 9, 2026Malware142
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News·Jun 6, 06:23 UTC · Jun 6, 2026Data breach57
Attackers already know the secrets are on your developers' machines. Do you?Help Net Security·Jun 4, 00:00 UTC · Jun 4, 2026Threat actor57
OpenAI Codex Authentication Tokens Stolen in codexuiThe Hacker News·Jun 1, 09:31 UTC · Jun 1, 2026Threat actor157
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential StealerThe Hacker News·May 25, 09:00 UTC · May 25, 2026Malware142
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIOThe Hacker News·May 25, 05:59 UTC · May 25, 2026Malware42
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain AttacksThe Hacker News·May 24, 08:15 UTC · May 24, 2026Industry142
GitHub, Grafana Labs breaches traced back to TanStack supply chain compromiseHelp Net Security·May 21, 00:00 UTC · May 21, 2026Vulnerability142
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain AttackThe Hacker News·May 15, 00:00 UTC · May 15, 2026Malware42
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS UpdatesThe Hacker News·May 15, 00:00 UTC · May 15, 2026Ransomware57
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain CompromiseThe Hacker News·May 8, 11:00 UTC · May 8, 2026Malware42
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential TheftThe Hacker News·May 1, 09:43 UTC · May 1, 2026Data breach57
Open source package with 1 million monthly downloads stole user credentialsArs Technica · Security·Apr 27, 21:04 UTC · Apr 27, 2026Vulnerability42
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 AttackThe Hacker News·Apr 27, 14:19 UTC · Apr 27, 2026Ransomware57
New linux_avp malware hits eCommerce sitesSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Malware42
Claude Code Source Leaked via npm Packaging Error, Anthropic ConfirmsThe Hacker News·Apr 3, 08:38 UTC · Apr 3, 2026Malware142
Hackers Hijack Axios npm Package to Spread RATsInfosecurity Magazine·Apr 1, 09:00 UTC · Apr 1, 2026Malware42
A Top Google Search Result for Claude Plugins Was Planted by Hackers404 Media·Mar 24, 13:35 UTC · Mar 24, 2026Malware42
Product showcase: Cross-platform and third-party endpoint patching with Action1Help Net Security·Mar 24, 00:00 UTC · Mar 24, 2026Ransomware in the wild60
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe BackdoorThe Hacker News·Feb 28, 04:41 UTC · Feb 28, 2026Malware42
Brutus: Open-source credential testing tool for offensive securityHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2026Malware42
Three Flaws in Anthropic MCP Git Server Enable File Access and Code ExecutionThe Hacker News·Jan 20, 13:55 UTC · Jan 20, 2026VulnerabilityCVE-2025-68143CVE-2025-68144CVE-2025-68145147
Supply chains, AI, and the cloud: The biggest failures (and one success) of 2025Ars Technica · Security·Dec 31, 13:15 UTC · Dec 31, 2025Data breach57
Traditional Security Frameworks Leave Organizations Exposed to AIThe Hacker News·Dec 29, 06:34 UTC · Dec 29, 2025Data breach57
Researcher Uncovers 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE AttacksThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025VulnerabilityCVE-2025-49150CVE-2025-53097CVE-2025-58335+8 CVEs147
AI-Enabled Malware Now Actively Deployed, Says GoogleInfosecurity Magazine·Nov 6, 09:45 UTC · Nov 6, 2025Malware42
Google uncovers malware using LLMs to operate and evade detectionHelp Net Security·Nov 5, 00:00 UTC · Nov 5, 2025Malware142
PhantomRaven Malware Found in 126 npm Packages Stealing GitHub Tokens From DevsThe Hacker News·Oct 30, 11:46 UTC · Oct 30, 2025Malware42
GitHub Mandates 2FA and Short-Lived Tokens to Strengthen npm Supply Chain SecurityThe Hacker News·Sep 25, 07:40 UTC · Sep 25, 2025Malware42
China-linked APT41 targets government, think tanks, and academics tied to USSecurity Affairs·Sep 17, 20:26 UTC · Sep 17, 2025Threat actor57
Chinese APT Actor Compromises Military Firm with Novel Fileless MalwarInfosecurity Magazine·Sep 11, 13:45 UTC · Sep 11, 2025Vulnerability42
Toptal GitHub Breach Exposes 73 Repositories and Injects Malware into 10 npm PackagesThe Hacker News·Aug 6, 10:50 UTC · Aug 6, 2025Malware42
GhostContainer backdoor for Exchange serversKaspersky Securelist·Jul 17, 08:00 UTC · Jul 17, 2025MalwareCVE-2020-068847
Cisco removed the backdoor account from its Unified Communications ManagerSecurity Affairs·Jul 2, 19:13 UTC · Jul 2, 2025MalwareCVE-2025-2030947
New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions GloballyThe Hacker News·Jun 9, 16:37 UTC · Jun 9, 2025Malware42
New Self-Spreading Malware Infects Docker Containers to Mine Dero CryptocurrencyThe Hacker News·May 27, 16:23 UTC · May 27, 2025Malware42