Malicious npm packages have been identified distributing malware that steals credentials and attempts to spread across ...
A new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 "sleeper" extensions that turn malicious ...
Two newly discovered macOS threats are designed to harvest developer credentials and cloud access as attackers focus on ...
A widely used open-source PyPI package, elementary-data, was compromised in a targeted attack that inserted infostealer malware via a GitHub Actions vulnerability. The malicious update, version 0.23.3 ...
A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named 'Snow' which includes a ...
This was not a case of stolen credentials, but rather of vulnerability exploitation.