New wave of “smishing” campaign impersonates toll agencies to steal payment data as cybercriminals scale operations across the U.S. and beyond A fast-growing text message scam...
The modern software supply chain is no longer confined to repositories, CI/CD pipelines, or cloud infrastructure. Security researchers are increasingly warning that developer workstations themselves have...
GitHub is investigating a significant security incident after attackers allegedly gained access to internal systems and exfiltrated thousands of private repositories following a compromise of an...
A Chinese national accused of ties to the hacking collective known as Silk Typhoon has been extradited from Italy to the United States, where he faces...
April 2026 — A critical SQL injection vulnerability in the widely used LiteLLM Python package has been actively exploited in the wild just 36 hours after...
April 2026 — Security researchers have disclosed a high-severity remote code execution (RCE) vulnerability affecting GitHub platforms that could allow an attacker with repository access to...
April 2026 — Security researchers have uncovered a severe and currently unpatched vulnerability in LeRobot, an open-source robotics framework developed under the Hugging Face ecosystem, that...
US and German cybersecurity agencies are urging organizations to address a severe vulnerability discovered in PTC’s Windchill and FlexPLM software products. The flaw, tracked as CVE-2026-4681,...
The threat actor TeamPCP, previously linked to supply chain attacks on Python packages like Trivy, KICS, and litellm, has now targeted the Telnyx Python package, publishing...
Apple has begun sending Lock Screen notifications to iPhones and iPads running outdated iOS and iPadOS versions, warning users of active web-based attacks and urging them...