Craneware, a healthcare finance software provider used by approximately 2,000 US hospitals, disclosed a breach on July 20 where hackers…
Read More »supply chain attack
A hacking group is exploiting the update system of ViPNet private networking software to infiltrate Russian government agencies, state-owned enterprises,…
Read More »A financially motivated Russian-speaking cybercriminal created 292 fraudulent GitHub repositories impersonating hundreds of brands, luring victims with fake "secure download"…
Read More »A security breach at Suno exposed internal data confirming the company scraped audio from YouTube Music, Deezer, and other services,…
Read More »Klue confirmed a security breach where attackers stole OAuth tokens from client Salesforce integrations after gaining access through a compromised…
Read More »At least 15 malicious plugins on the JetBrains Marketplace, masquerading as AI coding assistants and tools, have been discovered stealing…
Read More »Attackers compromised over 400 packages in the Arch Linux User Repository (AUR) to deploy a Rust-based credential stealer, which can…
Read More »On June 1, 2026, over 30 npm packages tied to Red Hat Cloud Services were compromised in a supply chain…
Read More »A malicious npm package named "codexui-android", with 29,000 weekly downloads and a legitimate appearance, secretly exfiltrated developer authentication tokens for…
Read More »GitHub confirmed a security breach after TeamPCP infiltrated its internal repositories via a compromised VS Code extension installed by an…
Read More »A GitHub employee's device was compromised after installing a malicious VS Code extension, leading to approximately 3,800 internal repositories being…
Read More »GitHub confirmed a breach that compromised approximately 3,800 internal code repositories after an employee's device was infected through a malicious…
Read More »The ransomware group Nitrogen claims to have stolen 8 TB of sensitive data, including schematics from major clients like Apple…
Read More »Disc Soft released a clean Version 12.6 of Daemon Tools Lite on May 5, just 12 hours after discovering a…
Read More »DAEMON Tools Lite was compromised in a supply chain attack affecting free version 12.5.1 installers served from the official website…
Read More »Trellix confirmed a data breach where unauthorized actors accessed a portion of its source code repository, with no evidence yet…
Read More »The GlassWorm campaign has deployed 73 sleeper extensions on the OpenVSX ecosystem, with only 6 activated so far delivering malware,…
Read More »Boost Security has launched SmokedMeat, an open-source framework that actively simulates end-to-end attack chains against an organization's own CI/CD infrastructure…
Read More »Hackers breached cloud platform Vercel by exploiting an employee's compromised Google account, which was linked to a third-party app from…
Read More »The official CPUID website, known for tools like HWMonitor, was compromised earlier this year, redirecting users to credential-stealing malware for…
Read More »


















