Aggregator
FTC considers setting aside or modifying $150 million privacy penalty against X
IronWorm Supply Chain Attack Uses Malicious npm Packages to Steal Developer Secrets
A newly discovered malware campaign called IronWorm has been silently targeting software developers through poisoned npm packages, stealing credentials, API keys, and even cryptocurrency wallet recovery phrases. The attack is built to spread itself through trusted developer workflows, making it one of the more sophisticated supply-chain threats seen in recent years. The malware travels inside […]
The post IronWorm Supply Chain Attack Uses Malicious npm Packages to Steal Developer Secrets appeared first on Cyber Security News.
Docker security advisory (AV26-550)
用魔法打败魔法:自动化越狱提示词的生成
js原型链污染原理及绕过
SGLang GGUF 投毒致 RCE 漏洞(CVE-2026-5760)
Letta AI 最新版未修复漏洞
DentaQuest data breach exposed info of 2.6 million accounts
Новые биологические часы умеют считать потерянные годы. И подсказывать, как часть из них отыграть назад
INC
You must login to view this content
Submit #832348: bytedance InfiniStore 0.2.33 Denial of Service [Accepted]
Submit #832308: LibreDWG libredwg main branch @0b57303 (latest as of 2026-04-29) Heap-buffer-overflow (Out-of-bounds Heap Write) [Duplicate]
Submit #832297: LibreDWG libredwg main branch @0b57303 (latest as of 2026-04-29) Heap-buffer-overflow (Out-of-bounds Heap Read) [Duplicate]
Your AI agent could become your biggest insider threat
New research details how the increasing integration of AI agents into businesses is making it easier than ever for insiders - malicious or otherwise - to put sensitive data at risk.
The post Your AI agent could become your biggest insider threat appeared first on CyberScoop.
Russia seeks to label two anti-Kremlin hacker groups as ‘extremist’
Stock Exchange Executive’s Outlook Account Targeted to Exfiltrate Credentials
A senior executive at a major global stock exchange had their Microsoft Outlook account silently compromised for five straight months, with attackers carefully siphoning emails in small batches to avoid detection. The intrusion ran from October 2025 through at least March 2026, designed entirely around one single goal: stealing the complete contents of one person’s […]
The post Stock Exchange Executive’s Outlook Account Targeted to Exfiltrate Credentials appeared first on Cyber Security News.