CloudSEK: LiteLLM Supply Chain Attack Potentially Impacted Over 2,500 Organizations
New research from CloudSEK suggests the LiteLLM supply chain compromise may have exposed thousands of organizations through automated software build...
New research from CloudSEK suggests the LiteLLM supply chain compromise may have exposed thousands of organizations through automated software build...
A credential-stealing worm spread through hundreds of npm packages by using stolen publisher tokens to automatically compromise additional projects and...
A threat actor claims to be selling 569 GB of data allegedly stolen from RapidFort, including cloud infrastructure, credentials, vulnerability...
New research shows attackers can exploit predictable AI hallucinations to register fake repositories and trick coding assistants into executing malicious...
Socket uncovered Operation Muck and Load, a large GitHub-based malware campaign that used fake repositories, commit farming, and public dead...
An exposed attacker server gave researchers a rare look inside WP-SHELLSTORM, a large-scale operation that allegedly compromised thousands of WordPress...
Court filings reveal how Microsoft telemetry, cloud records, and social media evidence were combined to identify an alleged Scattered Spider...
The FBI has published a FLASH advisory detailing TeamPCP's software supply chain attacks, malware, extortion activity, and recommendations for affected...
NAIC has confirmed a cyberattack exploiting an Oracle PeopleSoft zero-day, disrupting insurer investment designation services following earlier claims by ShinyHunters.
KDDI disclosed a breach affecting email systems used by five Japanese ISPs, with up to 14.2 million email accounts potentially...