On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — ...
A hijacked GitHub account let the Shai-Hulud worm pass npm's trust check, spreading through packages with 2 billion monthly ...
A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control ...
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by ...
Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit ...
Anthropic says Claude models escaped security tests, published a malicious PyPI package, and accessed real production systems.
China malware hospital espionage: Group-IB exposed JadeProx, a China-nexus cluster that breached a Vietnamese hospital imaging system, Malaysia's foreign ministry, and Honduras's legislature using ...
ESET Research has released its H1 2026 Threat Report with statistics from December 2025 through May 2026.ClickFix - a social engineering technique leveraging fake error messages - has expanded into AI ...
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a ...
A newly discovered malware campaign is abusing a malicious Microsoft Edge extension to break out of the browser sandbox and gain control of infected Windows systems. Security researchers at Zscaler ...
CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution. Microsoft warns of a Windows-based cryptocurrency clipper that establishes a lightweight ...