A hijacked GitHub account let the Shai-Hulud worm pass npm's trust check, spreading through packages with 2 billion monthly ...
Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents—the most serious case ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Microsoft Defender automatically isolated a compromised QNET endpoint in 129 seconds, stopping a multi-stage attack before the payload could persist or spread.
A self-spreading worm poisoned hundreds of npm packages in hours, slipped past provenance checks, hid its controls on Ethereum, and hunted AI-tool keys.
A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control ...
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by ...
Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit ...
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security ...
Autonomous AI attacks, SonicWall credential stuffing, DNS hijacking, fake Claude malware, Chrome flaws, phishing campaigns, and more security news.