OpenAI Confirms Internal Breach Linked to Mini Shai-Hulud Supply-Chain Attack
OpenAI confirmed that two employee devices were compromised in the Mini Shai-Hulud supply-chain attack, exposing some internal source code and...
OpenAI confirmed that two employee devices were compromised in the Mini Shai-Hulud supply-chain attack, exposing some internal source code and...
A threat actor claims to have breached UK-based AimSmarter on May 11, 2026, exposing 6,500 business and employee records including...
The Mini Shai-Hulud malware campaign exploits trusted npm and PyPI CI/CD pipelines to propagate malicious packages across projects like TanStack...
The ShinyHunters group claims to have breached Colombian fintech Addi, exposing sensitive financial, credit, and personal data of over 16...
A malicious version of Bitwarden CLI was distributed via npm in a TeamPCP-linked supply chain attack, exposing developer credentials and...
FulcrumSec claims to have breached Hatica and its subsidiaries DixiApp and Posium, exposing data including 4,700 active Slack workspace tokens,...
Vercel confirmed a breach exposing internal systems and some customer data, with ShinyHunters claiming to sell the stolen access keys,...
A fake Ledger Live app on Apple’s App Store stole $9.5 million from over 50 victims in six days by...
Bitcoin Depot confirmed the theft of approximately $3.665 million in Bitcoin after attackers compromised corporate settlement account credentials, with the...
Cisco Talos uncovered an extensive automated credential theft campaign exploiting the critical React2Shell vulnerability (CVE-2025-55182), compromising 766 hosts and targeting...