A high-severity security vulnerability has been discovered in Gogs, a widely used open-source self-hosted Git service, that allows authenticated users to execute arbitrary code on affected...
Cybersecurity researchers have uncovered a coordinated wave of software supply chain attacks involving malicious packages published to both NuGet and npm registries, designed to steal sensitive...
A critical security vulnerability in FortiClient Endpoint Management Server (EMS) is being actively exploited by threat actors to distribute a newly identified credential-stealing malware known as...
Microsoft has strongly criticized the public disclosure of multiple zero-day vulnerabilities affecting Windows systems, reaffirming its support for Coordinated Vulnerability Disclosure (CVD) and warning that premature...
A high-severity vulnerability in the KnowledgeDeliver LMS platform has been actively exploited as a zero-day to deliver web shells and post-exploitation malware, including Cobalt Strike Beacon....
Advanced Phishing, SEO Poisoning, and Fake Software Installers Used to Spread MiniFast and MiniJunk V2 A state-linked Iranian cyber espionage group identified as Nimbus Manticore, also...
Hackers are actively exploiting a high-severity vulnerability in Ghost CMS to inject malicious scripts and run widespread ClickFix browser-based attacks across compromised websites. Cybersecurity researchers have...
North Korea-linked threat actors deploy advanced multi-stage RemotePE remote access trojan designed for ultra-stealthy, fileless espionage against high-value financial and cryptocurrency targets. Cybersecurity researchers have uncovered...
MAY 23, 2026 — A coordinated software supply chain attack has compromised eight packages on Packagist, the main repository for PHP dependencies, after attackers injected malicious...
SAN FRANCISCO — GitHub has launched a new set of security upgrades for npm designed to reduce software supply chain attacks, introducing two-factor authentication (2FA)-gated publishing...