GitHub facades and Ethereum smart contracts power a March 2026 admin-targeted campaign, enabling resilient C2 rotation and ...
Google has rolled out Chrome version 147.0.7727.137/138 for desktop and Android, fixing 30 security vulnerabilities, including four critical ones. On the same day, Apple released firmware 8B40 for ...
Multiple SAP npm packages were compromised in a supply chain attack designed to steal developer credentials and tokens.
Malicious Lightning 2.6.2/2.6.3 released April 30 enable credential theft via hidden payload, leading to PyPI quarantine and ...
Four SAP NPM packages compromised in the Mini Shai-Hulud supply chain attack trigger a Bun runtime to install an information ...
Researchers say the campaign targeted developer credentials and cloud secrets while abusing trusted publishing and AI coding ...
A threat group planted a malicious npm package in a crypto trading project through an AI-generated commit by Anthropic's ...
Several npm packages for SAP's cloud application development ecosystem have been compromised as TeamPCP's supply chain ...
Socket’s acquisition of Secure Annex extends software supply-chain security beyond open-source dependencies into browser and ...
Google has released Chrome version 147.0.7727.137/138 for desktop and Android, fixing 30 security vulnerabilities, including four critical use‑after‑free flaws. While no active exploitation has been ...