Malicious VSCode extensions with millions of installs discovered
A group of Israeli researchers explored the security of the Visual Studio Code marketplace and managed to "infect" over 100…
A group of Israeli researchers explored the security of the Visual Studio Code marketplace and managed to "infect" over 100…
AI platform Hugging Face says that its Spaces platform was breached, allowing hackers to access authentication secrets for its members.…
Ransomware groups have always created problems for their victims that only they could solve. Black Basta is taking that core…
In an ongoing Kubernetes cryptomining campaign, attackers target OpenMetadata workloads using critical remote code execution and authentication vulnerabilities. [...]
Suspected state-sponsored hackers have been exploiting a zero-day vulnerability in Palo Alto Networks firewalls tracked as CVE-2024-3400 since March 26,…
One issue would have allowed cross-tenant attacks, and another enabled access to a shared registry for container images; exploitation via…
Hackers are targeting misconfigured servers running Apache Hadoop YARN, Docker, Confluence, or Redis with new Golang-based malware that automates the…
A new malware dubbed 'WogRAT' targets both Windows and Linux in attacks abusing an online notepad platform named 'aNotepad' as…
At least 100 instances of malicious AI ML models were found on the Hugging Face platform, some of which can…
Both China-backed APTs and ordinary cyberattackers have seized on a pair of Ivanti VPN bugs for global exploitation.