FEATURE Two supply chain attacks in March infected open source tools with malware and used this access to steal secrets from ...
Meta pauses Mercor partnership after a major data breach raises concerns over exposure of sensitive AI training data.
Strapi plugins exploit Redis and PostgreSQL via postinstall scripts, enabling persistent access and data theft.
JFrog reports Telnyx PyPI package was poisoned with malware by TeamPCP Malicious update delivered hidden .wav payload that deployed infostealer and persistence mechanisms Users advised to downgrade, ...