NodeStealer now steals data and adds keylogging, clipboard monitoring, and screen capture, expanding into full surveillance.
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an ...
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates ...
Australian authorities have charged two alleged TeamPCP members after software supply chain attacks exposed over 500,000 credentials and at least 300GB of data.
ChatGPT may spew a lot of digital garbage onto the internet, but the same bots that output the trash can be used to stop it.
We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK, that lets any user grant themselves admin control over marker accounts without holding a single ...
A previously undocumented malware loader, dubbed SynkLoader, that combines Python, C#, and native C++ components to evade ...
SynkLoader malware is spreading through Microsoft Teams phishing, using a fake Windows lock screen to steal credentials and enable remote access.
A Python-based malware framework is taking the concept of living off the land (LOTL) to a whole new level by operating its entire command-and-control (C2) from inside Microsoft Azure and 365 services, ...
On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP ...
Bob Bramblet is a Lee County Sheriff's Office employee, outdoorsman, and award-winning writer. He hunts invasive Burmese pythons in the Everglades to protect native wildlife. Bramblet has written a ...
Microsoft released a record number of security patches for Windows, Office, and other tech product lines this week, citing the use of AI to aid the discovery of code vulnerabilities. The technology ...