IncidentThree Package Repos Hit in 48 Hours
What Happened Between late 2024 and early 2025, three separate credential-harvesting campaigns targeted npm , PyPI, and Docker Hub within a 48-hour period. These attacks followed a common pattern: com
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened Between late 2024 and early 2025, three separate credential-harvesting campaigns targeted npm , PyPI, and Docker Hub within a 48-hour period. These attacks followed a common pattern: com
IncidentA research team at Xidian University has demonstrated a new type of attack that manipulates multimodal AI systems through altered images. This attack, called CrossMPI, achieved a 66.36% average succes
IncidentWhat Happened Between late March and early April 2025, attackers began exploiting CVE-2026-42945 , a critical vulnerability in NGINX that allows denial-of-service attacks and potential remote code exe
IncidentWhat Happened Attackers are actively exploiting CVE-2026-42945 , a heap buffer overflow in NGINX s ngx_http_rewrite_module . VulnCheck detected exploitation attempts against their honeypot networks. T
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened The DARPA Artificial Intelligence Cyber Challenge (AIxCC) concluded with a $30,500,000 prize pool, showcasing AI s potential in vulnerability detection. Seven teams deployed AI systems a
IncidentSecureLayer7 released Sandyaa in late 2024 under an MIT license. This tool uses large language models to scan source code for vulnerabilities and then writes exploit code to prove they re real. Within
IncidentA critical authentication bypass in the Burst Statistics WordPress plugin gave attackers admin-level access to thousands of websites. Here s what happened, which controls failed, and what your team ne
IncidentIncident Overview Attackers compromised the node-ipc npm package by exploiting an expired domain linked to a maintainer s account. They published malicious versions (11.0.0, 11.1.0, and 12.0.0) contai
IncidentWhat Happened Between early December 2024 and January 16, 2025, attackers exploited a critical vulnerability in FunnelKit s Funnel Builder plugin to inject malicious JavaScript into WooCommerce checko
IncidentWhat Happened On April 13, Microsoft rejected a security researcher s vulnerability report for Azure Backup for AKS (Azure Kubernetes Service). The researcher, Justin O Leary, identified a privilege e
IncidentDiscovery of a Long-Overlooked Vulnerability An AI-powered security agent uncovered a vulnerability that had eluded human researchers for over a decade, exploiting it within 48 hours of deployment. Th
IncidentWhat Happened TeamPCP compromised Mistral AI s codebase management system, extracting nearly 450 repositories. They are selling the complete source code for $25,000 on underground forums, threatening
IncidentWhat Happened In early 2025, threat actor TeamPCP compromised TanStack s distribution infrastructure and released trojanized versions of npm and PyPI SDKs. Two OpenAI employee devices installed these
IncidentOn May 14, 2026, three malicious versions of node-ipc—a package with millions of weekly downloads—were published to npm. These versions (9.1.6, 9.2.3, and 12.0.1) contained a credential-stealing paylo
IncidentWhat Happened On May 12, Wordfence disclosed two vulnerabilities in the Avada Builder WordPress plugin, which has an estimated one million active installations. CVE-2026-4782 allows arbitrary file rea
IncidentA vulnerability in the Funnel Builder WordPress plugin allowed attackers to inject malicious JavaScript into WooCommerce checkout pages and harvest credit card data in real time. The plugin, active on