Cursor Issue Paves Way for Credential-Stealing Attacks
(darkreading.com)
91.
92.
150,000 Packages Flood NPM Registry in Token Farming Campaign
(darkreading.com)
95.
96.
Malicious NuGet packages drop disruptive 'time bombs'
(bleepingcomputer.com)
97.
Supply chain attacks are exploiting our assumptions
(news.ycombinator.com)
99.
Gootloader malware is back with new tricks after 7-month break
(bleepingcomputer.com)
100.
The Top 3 Browser Sandbox Threats That Slip Past Modern Security Tools
(bleepingcomputer.com)
101.
Fake Solidity VSCode extension on Open VSX backdoors developers
(bleepingcomputer.com)
102.
Open VSX rotates access tokens used in supply-chain malware attack
(bleepingcomputer.com)
103.
Show HN: I built a tech news aggregator that works the way my brain does
(news.ycombinator.com)
104.
The security paradox of local LLMs
(news.ycombinator.com)
105.
CISA: High-severity Windows SMB flaw now exploited in attacks
(bleepingcomputer.com)
106.
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
(bleepingcomputer.com)
108.
Hackers can steal 2FA codes and private messages from Android phones
(arstechnica.com)
109.
110.
Malicious Rust packages on Crates.io steal crypto wallet keys
(bleepingcomputer.com)
111.
NPM package caught using QR Code to fetch cookie-stealing malware
(bleepingcomputer.com)
112.
Hidden risk in Notion 3.0 AI agents: Web search tool abuse for data exfiltration
(news.ycombinator.com)
113.
CISA exposes malware kits deployed in Ivanti EPMM attacks
(bleepingcomputer.com)
114.
Tinycolor supply chain attack post-mortem
(news.ycombinator.com)
115.
Microsoft adds malicious link warnings to Teams private chats
(bleepingcomputer.com)
116.
Hackers left empty-handed after massive NPM supply-chain attack
(bleepingcomputer.com)
117.
Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack
(bleepingcomputer.com)
118.
6 browser-based attacks all security teams should be ready for in 2025
(bleepingcomputer.com)
119.
Threat actors abuse X’s Grok AI to spread malicious links
(bleepingcomputer.com)