ThreatsDay: Malicious VS Code themes, npm supply-chain attacks, AI phishing, ransomware betrayal, exposed hacker tools, and ...
Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised ...
GlassWorm-linked VS Code extensions abuse theme packages, obfuscated JavaScript, AES-256-CBC, and Solana dead drops to ...
Horizon3.ai researchers used Anthropic's Mythos model to find a cryptographic weakness in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500. The flaw lets an unauthenticated attacker forge ...
GlassWorm hides malware in VS Code theme extensions, targeting developers through Visual Studio Marketplace and Open VSX.
A group of VS Code theme extensions linked to GlassWorm, a malware campaign targeting developers. Their investigation ...
Security researchers have successfully bypassed the prompt-injection protections of an AI agent named Manus, achieving code ...
A report published by Google's Threat Intelligence Group (GTIG) on September 9, 2026, details MCP server hijacking and supply ...
I curate AI and DX-related news every morning, generate product ideas from them, and experiment by building and releasing an ...