NullReceiver lets two North Korea-linked npm packages decode a C2 IP from blank Ethereum transfers without smart contracts or ...
HashiCorp, Veeam, and Django patch 11 flaws, including cross-tenant token reuse, agent credential exposure, and possible code ...
Paperclip flaws could let attackers run commands on servers or developer machines; v2026.416.0 adds import checks and ...
Researchers find more than six illegal AI access ads, including Poison Claude, which claims 5-15% pricing while its operator ...
CISA adds three exploited Langflow, Tomcat, and N-central flaws to KEV, while Unit 42 links one campaign to a ...
Kali365 targets US organizations with attacker-controlled device codes, potentially exposing Microsoft 365 email, files, and ...
GitGuardian found 321 n8n instances accepting leaked GitHub tokens that could expose workflows, data, and downstream ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
CVE-2026-64531 lets local users exploit Open vSwitch kernel memory corruption to gain root, with a public PoC covering ...
Anthropic's Claude Mythos 5 spent 34 hours trying to backdoor an open-source project, then used a sockpuppet and rewrote Git ...
A trojanized QuickFox Windows installer delivered FDMTP in a supply chain attack active since at least August 2025, after ...
Greatness PhaaS adds device code phishing to bypass MFA and steal OAuth tokens alongside AiTM and consent abuse.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results