A Vercel employee's AI tool OAuth grant gave attackers access to internal systems via a four-hop kill chain. Here's what ...
Attackers published a malicious command-line version of the popular open-source password manager to the npm registry and may ...
Vercel confirmed a security incident involving unauthorized access to internal systems, stemming from a compromised ...
VectorCertain LLC today announced new validation results demonstrating that its SecureAgent platform successfully detected ...
A new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 "sleeper" extensions that turn malicious ...
Three supply chain attacks hit npm, PyPI, and Docker Hub between April 21–23, 2026. All three targeted secrets: API keys, cloud credentials, SSH keys, and tokens from developer environments and CI/CD ...
Bitwarden CLI 2026.4.0 was compromised in a supply chain attack that targets crypto wallet keys, SSH keys, and CI/CD secrets.
Self-propagating npm worm steals tokens via postinstall hooks, impacting six packages and expanding supply chain attacks.
Etherpad is a self-hostable web editor written in Node.js for real-time collaborative writing – functionally comparable to ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results