One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security ...
Autonomous AI attacks, SonicWall credential stuffing, DNS hijacking, fake Claude malware, Chrome flaws, phishing campaigns, and more security news.
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ...
GitHub now automatically holds suspicious Actions workflows in public repositories, but maintainers must still review ...
Automate the process of grouping thousands of search queries into coherent topics for faster, more scalable content planning.
The OpenAI agent sandbox breach let the system escape its evaluation environment and reach Hugging Face infrastructure.
Gitea fixes CVE-2026-60004, a 9.8 RCE that lets repository writers turn malicious patches into Git hooks and run commands.
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, ...
GitHub’s Dependabot waits three days before opening pull requests, and PyPI rejects file uploads to releases older than 14 ...
China malware hospital espionage: Group-IB exposed JadeProx, a China-nexus cluster that breached a Vietnamese hospital ...
A Serilog.File.Sink hook that encrypts log files using RSA and AES-GCM hybrid encryption. This package provides secure logging by encrypting log data before writing to disk, ensuring sensitive ...