Security researchers have detailed MALFEX, an npm supply-chain campaign that uses eight malicious packages to deliver remote ...
Your vulnerability scanner is sorting by the wrong signal. How to use CVSS, EPSS, and local context to prioritize remediation ...
Baku data highlights how gearbox ratios, energy management and aero efficiency could shape Ferrari’s challenge under Formula ...
For a few years now, the PS5 hacking community has been chipping away at various exploits that let users fully jailbreak ...
A critical attack path in OpenCode, the open-source AI coding agent, could allow a malicious website to execute commands on a ...
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than ...
Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. SecurityWeek’s weekly ...
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In ...
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney ...
A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation builder for remote code execution (RCE), and ...
Jellyfin has released version 12.0, introducing multiple security fixes that address unauthorized file-access risks, cross-site scripting (XSS) weaknesses, insecure plugin package handling, and ...