Chainguard, the trusted foundation for software development and deployment, today announced Chainguard Libraries for JavaScript, a collection of trusted builds of thousands of common JavaScript ...
Process improvements and a closer look at funding streams will provide far more protection for the open source software we ...
Stripe iframe skimmer hit 49 merchants in Aug 2024, bypassing CSP to steal cards, driving PCI DSS 4.0.1 updates.
A newly-discovered malicious package with layers of obfuscation is disguised as a utility library, with malware essentially ...
In light of recent cyberattacks and growing security concerns, GitHub is taking immediate and direct action to secure the ...
Newly discovered npm package 'fezbox' employs QR codes to hide a second-stage payload to steal cookies from a user's web browser. The package, masquerading as a utility library, leverages this ...
Oracle has recently announced MySQL AI, a new set of AI-powered capabilities available exclusively in the MySQL Enterprise edition, targeting analytics and AI workloads in large deployments. Concerns ...
Two malicious packages with nearly 8,500 downloads in Rust's official crate repository scanned developers' systems to steal ...
Security experts warn of an AppSuite malware, TamperedChef, a trojanized PDF editor stealing data and deploying ransomware.
The security researchers who discovered the malicious npm package called it the “first malicious MCP in the wild” ...
ESET researchers reveal how malware operators collaborate with covert North Korean IT workers, posing a threat to both headhunters and job seekers.
ComicForm phishing since April 2025 targets Belarus, Kazakhstan, Russia using Formbook malware, evading Microsoft Defender.