GitHub pulls pin on npm’s auto-run scripts
Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors Continue reading GitHub pulls pin on npm’s auto-run scripts
Collaborate Disseminate
Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors Continue reading GitHub pulls pin on npm’s auto-run scripts
Remote, unauthenticated RCE with root privileges is about as bad as it gets Continue reading Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9
Unless you’re an admin or vulnerability manager – then you’re totally screwed Continue reading AI is making Patch Tuesday (kinda) fun again
As if there weren’t enough package poisonings to worry about Continue reading Miasma worms its way onto GitHub as attack kit goes open source
iBiz might not win the AI race, but analysts say it’s focusing on features people may actually use Continue reading Apple’s iOS 27 goes all agentic on compromised passwords, promises to change them with one tap
Encrypted messaging app warns device-level checks could be repurposed for censorship Continue reading Signal says UK plan to scan devices for nude images ‘endangers us all’
Google paid researcher a tidy $55K bounty for its discovery Continue reading Chrome’s zero-day Whac-A-Mole continues with fifth exploited bug of the year
Authorities say the breach only exposed public chat rooms, but alleged attacker claims to have accessed far more data Continue reading France probes compromise of gov messaging platform after account hijack
Two years on from ransomware attack, hospitals are still trying to identify and warn patients Continue reading Qilin NHS breach tally grows as Essex trust confirms stolen records
When an unsolicited job offer sounds too good to be true … Continue reading Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto