Bitwarden CLI Compromised in TeamPCP Supply Chain Attack Targeting Developer Secrets
A malicious version of Bitwarden CLI was distributed via npm in a TeamPCP-linked supply chain attack, exposing developer credentials and...
A malicious version of Bitwarden CLI was distributed via npm in a TeamPCP-linked supply chain attack, exposing developer credentials and...
A Florida ransomware negotiator pleaded guilty to conspiracy for secretly assisting the BlackCat group by sharing confidential victim information during...
An extortion group claims to have leaked 2.2 terabytes of data, including Guyana's Geology and Mines Commission database, from mining...
FulcrumSec claims to have breached Hatica and its subsidiaries DixiApp and Posium, exposing data including 4,700 active Slack workspace tokens,...
Vercel confirmed a breach exposing internal systems and some customer data, with ShinyHunters claiming to sell the stolen access keys,...
Iranian-linked group Handala claims it accessed Israel's GNS Cloud for 18 months, extracting passwords and backdooring 112,000 machines, posing severe...
A claimed breach of Infodesk reportedly exposed staff names and emails from 18 global organizations, including Johnson & Johnson and...
Cisco Talos uncovered an extensive automated credential theft campaign exploiting the critical React2Shell vulnerability (CVE-2025-55182), compromising 766 hosts and targeting...
TeamPCP is a financially motivated cybercrime group active since 2025, known for disrupting supply chains through attacks on developer tools,...
Mercor, an AI data startup serving OpenAI, Anthropic, and Meta, suffered a supply chain attack via the LiteLLM library, exposing...
Tools and intelligence from BreachNews.