Backdoored Rust packages hit crates.io, exposing developers to malware at build time
Malicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor tha...
Malicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor tha...
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head...
Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse. New research sh...
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. ...
Threat actors are exploiting interest in generative AI software to distribute the Vidar information stealer through a fake Google Gemini installer hosted via...
A malicious update to the Rust crate called onering has been discovered, which exfiltrates source code changes from developers’ machines during the build pro...
A phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly ...
Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate ...
Over 50,000 Stripe API keys have been exposed across public code repositories, GitHub Actions logs, and misconfigured web servers, demonstrating the immediat...
Socket researchers identified 40 malicious extensions and 37 others disguised as unrelated utilities, all linked through shared code, infrastructure, and pub...
Discovered by Zimperium's zLabs team, ToxicPanda 2.0 leverages the Android Accessibility Service to enable wireless debugging, effectively gaining shell acce...
A critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If explo...
The database, belonging to U.S.
Sakura Internet, a key provider of digital infrastructure services in Japan and a domestic partner for the Government Cloud program, discovered the breach on...
The campaign, originating from an IPv6 range provided by LSHIY LLC, leveraged reused credentials and the legacy Resource Owner Password Credentials (ROPC) OA...
The AI SAST agent identifies vulnerabilities, including logic flaws missed by traditional tools, and reduces false positives.
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network pattern...
The hacking group, identified as Salt Typhoon, compromised hundreds of companies, including major players like AT&T, Verizon, Viasat, Charter, and Windst...
Security researchers have demonstrated a “Zombie Card” attack that can reactivate certain expired Visa contactless cards, allowing them to be used for NFC pa...
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Expl...