OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that’s targeting developers using OpenAI Codex through a legitimate-looking remote web UI.

The tool, named codexui-android, is advertised on GitHub and npm as a … Continue reading OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Posted in Uncategorized

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of… Continue reading PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Posted in Uncategorized

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerabi… Continue reading Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

Posted in Uncategorized

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

Shadow AI used to mean employees pasting things they shouldn’t into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or… Continue reading What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

Posted in Uncategorized

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil’s largest cooperative financial systems, to siphon client IDs and PFX certificates.

According to Socket, ve… Continue reading Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

Posted in Uncategorized