HalluSquatting Exploits AI Coding Assistants to Deliver Malware
New research shows attackers can exploit predictable AI hallucinations to register fake repositories and trick coding assistants into executing malicious...
New research shows attackers can exploit predictable AI hallucinations to register fake repositories and trick coding assistants into executing malicious...
Socket uncovered Operation Muck and Load, a large GitHub-based malware campaign that used fake repositories, commit farming, and public dead...
An exposed attacker server gave researchers a rare look inside WP-SHELLSTORM, a large-scale operation that allegedly compromised thousands of WordPress...
Court filings reveal how Microsoft telemetry, cloud records, and social media evidence were combined to identify an alleged Scattered Spider...
The FBI has published a FLASH advisory detailing TeamPCP's software supply chain attacks, malware, extortion activity, and recommendations for affected...
NAIC has confirmed a cyberattack exploiting an Oracle PeopleSoft zero-day, disrupting insurer investment designation services following earlier claims by ShinyHunters.
KDDI disclosed a breach affecting email systems used by five Japanese ISPs, with up to 14.2 million email accounts potentially...
LastPass has confirmed customer support records and contact information were stolen during the Klue supply chain breach, joining a growing...
Icarus has added Huntress and four additional organizations to its leak site, claiming to possess Salesforce data allegedly stolen through...
International law enforcement disrupted SocGholish infrastructure linked to Evil Corp, cleaned nearly 15,000 websites, and identified 154,000 impacted email addresses.