Tag: source
120 articles

Supply chain attack hits npm package with 45,000 weekly downloads
Supply chain attack compromises an npm package with 45,000 weekly downloads. Learn how to secure your dependencies and mitigate emerging threats.

PyPi Package Conceals RAT Malware, Targeting Discord Developers Since 2022
PyPi package camouflages RAT malware targeting Discord developers since 2022, exposing a dangerous supply chain threat.

Researchers Discover Malware in Bogus Discord PyPI Package Accumulating Over 11,500 Downloads
Researchers uncovered malware in a fake Discord PyPI package, racking up over 11,500 downloads and sparking significant cybersecurity alerts.

New Exploit Tool Uncovers Critical Vulnerabilities in Apache Parquet Servers
New exploit tool exposes critical vulnerabilities in Apache Parquet servers, prompting urgent patching and heightened security measures.

Linux Wiper Malware Disguised as Malicious Go Modules on GitHub
Linux Wiper Malware hides in GitHub Go modules, targeting Linux systems. Learn about its deceptive tactics and potential system erasure threats.

Urgent Update: Langflow Vulnerability Added to CISA KEV List Amid Active Exploits
Urgent update: Langflow vulnerability added to the CISA KEV list amid active exploits. Act now to secure your systems and safeguard your data.

Signal chat app clone used by Signalgate’s Waltz was apparently an insecure mess
Signalgate’s Waltz used a cloned Signal chat app riddled with security flaws, exposing critical vulnerabilities and putting user data at risk.

Open-Source Platforms Offer Enhanced Security Over Proprietary Systems
Open-source platforms deliver enhanced security through transparent code, rapid patches, and active community oversight, outperforming proprietary systems.

Linux Disk-Wiping Malware Exploits Go Modules in Sophisticated Supply Chain Attack
Linux disk-wiping malware exploits compromised Go modules in an advanced supply chain attack, targeting systems and causing significant data loss.

Malicious PyPI packages abuse Gmail, websockets to hijack systems
Malicious PyPI packages exploit Gmail and websockets to hijack systems, raising cybersecurity concerns and necessitating enhanced threat detection mechanisms.

Meta Unveils New Advances in AI Security and Privacy Protection
Meta unveils innovative AI security and privacy protocols, enhancing data protection and real-time threat detection for a safer digital experience.

Meta Launches LlamaFirewall Framework to Stop AI Jailbreaks, Injections, and Insecure Code
Meta launches LlamaFirewall, a robust framework preventing AI jailbreaks, injections, and insecure code to enhance system security.

Cyberattack on World Uyghur Congress Leaders Using Compromised UyghurEdit++ Tool
Cyberattack on World Uyghur Congress leaders exploits a compromised UyghurEdit++ tool—revealing breach details and raising global security concerns.

Kali Linux Faces Update Errors After Losing Its Repository Signing Key
Kali Linux update errors emerge from a lost repository signing key, leading to security risks and failed updates. Learn about fixes and solutions.

New Research Uncovers Rack::Static Flaw
New research reveals a critical flaw in Rack::Static, exposing potential security risks and offering insights for safeguarding your applications.

Linux ‘io_uring’ security blindspot allows stealthy rootkit attacks
Linux io_uring security flaw exposes a blindspot that enables stealthy rootkit attacks, undermining system integrity and privileged escalation safeguards.

Chainguard Secures $356M to Safeguard Open-Source Supply Chains
Chainguard secures $356M to enhance security for open-source supply chains, ensuring safer software development and protecting against vulnerabilities.

Major Supply Chain Attack: Ripple’s xrpl.js npm Package Compromised to Steal Private Keys
Ripple’s xrpl.js npm package was compromised in a major supply chain attack, leading to the theft of private keys from unsuspecting users.

Windows 10 KB5055612 Preview Update Resolves GPU Issue in WSL2
Windows 10 KB5055612 Preview Update fixes GPU issues in WSL2, enhancing performance and stability for developers and users.

The Hidden Dangers of AI-Driven Slopsquatting in Supply Chains
Explore the hidden dangers of AI-driven slopsquatting in supply chains, revealing risks to efficiency, security, and ethical practices.

Malicious npm Packages Imitate Telegram Bot API to Install SSH Backdoors on Linux
Malicious npm packages mimic the Telegram Bot API to install SSH backdoors on Linux, posing serious security risks for developers and systems.

New Malicious PyPI Package Exploits MEXC Trading API to Hijack Credentials and Orders
New malicious PyPI package targets MEXC Trading API, hijacking user credentials and orders, posing serious security risks for traders.

Severe Apache Roller Vulnerability (CVSS 10.0) Allows Unauthorized Session Persistence
Severe Apache Roller vulnerability (CVSS 10.0) enables unauthorized session persistence, risking user data and system integrity. Immediate patching recommended.

Chinese Cyberattackers Exploit Linux with SNOWLIGHT Malware and VShell Tool
Chinese cyberattackers leverage SNOWLIGHT malware and VShell tool to exploit Linux systems, posing significant security threats to organizations.