IncidentTwo npm Packages Hijacked in One Week
On January 13, 2025, AsyncAPI discovered that several of its npm packages had been compromised and were distributing malware. Three days later, Jscrambler reported a similar incident affecting its pac
Expert perspectives on application security, compliance, and emerging threats
IncidentOn January 13, 2025, AsyncAPI discovered that several of its npm packages had been compromised and were distributing malware. Three days later, Jscrambler reported a similar incident affecting its pac
IncidentBetween June 29 and July 3, 2026, a threat actor published seven malicious npm packages targeting developers using Vite, a popular frontend build tool. Checkmarx discovered the campaign, dubbed ViteVe
IncidentA Go-based botnet named NadMesh has been actively scanning for exposed AI services and harvesting cloud credentials. Research from QiAnXin s XLab reveals that the botnet s operator claims to have coll
IncidentWhat Happened OpenAI s automated red-teaming system, GPT-Red, successfully attacked a production AI agent and convinced it to reprice inventory. Items normally priced above $100 were marked down to $0
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened Bugcrowd recently revised its submission policies after a surge of low-quality, AI-generated vulnerability reports. Researchers submitted findings that looked polished but lacked proof t
IncidentThe Problem In 2024, CISA and four international cybersecurity agencies released joint guidance urging software vendors to establish formal coordinated vulnerability disclosure (CVD) programs. This wa
IncidentOn June 24, 2026, n8n patched CVE-2026-59208, a vulnerability in their token exchange mechanism that allowed attackers to authenticate as users from a different token issuer. If your Enterprise instan
IncidentSAP s July 2026 security update included CVE-2026-44747 , an out-of-bounds write vulnerability in NetWeaver Application Server ABAP with a CVSS score of 9.9. This flaw allows an authenticated attacker
IncidentWhat Happened Between May and July 2026, attackers exploited CVE-2026-46817 , a critical Oracle E-Business Suite vulnerability that allows unauthenticated remote code execution. Oracle released a patc
IncidentWhat Happened OpenAI used GPT-Red, an automated adversarial testing system, to identify prompt injection vulnerabilities in GPT-5.6 Sol before its release. The testing showed that earlier versions wer
IncidentWhen the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published new guidance on coordinated vulnerability disclosure programs in late 2024, it admitted its own reporting channels had f
IncidentIn December 2024, researchers at Seoul National University demonstrated a new attack that made AI agents perform unintended actions. This attack succeeded up to 50% of the time against current defense
IncidentWhat Happened Anthropic s Claude for Chrome extension has two vulnerabilities that allow malicious browser extensions to hijack the AI s capabilities to read and exfiltrate user data. Security researc
IncidentWhat Happened Progress Software discovered a zero-day vulnerability in ShareFile Storage Zone Controllers and made an unusual decision: release patches immediately but delay the CVE publication for tw
IncidentOn July 14, a misconfigured GitHub Actions workflow turned AsyncAPI s npm packages into a distribution channel for credential-stealing malware. The attack lasted just over four hours, but the packages
IncidentIntruder s security research team discovered a SQL injection vulnerability in the Creative Mail plugin for WordPress using an automated pipeline that combines traditional code scanning with AI analysi