The packages deployed malicious code harvesting system information, credentials, tokens, API keys, and other sensitive information.
Hi, what are you looking for?
The packages deployed malicious code harvesting system information, credentials, tokens, API keys, and other sensitive information.
Peter Williams stole trade secrets from his US employer and sold them to a Russian cybersecurity tools broker.
The company has built a plug-and-play photonic layer transmission system that encrypts data in transit to prevent interception.
Exploits have been available publicly for over half a year, but the bug was previously targeted only for reconnaissance.
Starting October 2026, the browser will ask users if they want to access public websites that do not use secure connections.
Two DELMIA Apriso flaws can be chained together to gain privileged access to the application and execute arbitrary code remotely.
The critical-severity flaw allows attackers to smuggle HTTP requests and access sensitive data, modify server files, or cause DoS conditions.
A new class of Mirai-based DDoS botnets have been launching massive attacks, but their inability to spoof traffic enables device remediation.
The email addresses were pulled from various sources and 16.4 million of them were not present in previous data breaches.
The hackers stole information from a file transfer solution and the country’s power supply was not affected.
The malicious Smishing Triad domains were used to collect sensitive information, including Social Security numbers.
All new extensions will be required to declare their data collection practices in their manifest file using a specific key.
Roughly 9 million exploit attempts were observed this month as mass exploitation of the critical vulnerabilities recommenced.
The threat actor behind Operation ForumTroll used the same toolset typically employed in Dante spyware attacks.
Shortly after the browser was launched, numerous fraudulent domains and fake applications were discovered.
Lazarus has used fake job offers in attacks targeting companies developing UAV technology, for information theft.
The customer information published on the dark web includes names, addresses, phone numbers, and email addresses.
In files downloaded from the internet, HTML tags referencing external paths could be used to leak NTLM hashes during file previews.
The relationship between the Russian government and cybercriminal groups has evolved from passive tolerance.
Patched in September, the SessionReaper bug could be exploited without authentication to bypass a security feature.