Cursor Issue Paves Way for Credential-Stealing Attacks
(darkreading.com)
181.
182.
150,000 Packages Flood NPM Registry in Token Farming Campaign
(darkreading.com)
184.
186.
187.
Malicious NuGet packages drop disruptive 'time bombs'
(bleepingcomputer.com)
188.
Supply chain attacks are exploiting our assumptions
(news.ycombinator.com)
190.
Gootloader malware is back with new tricks after 7-month break
(bleepingcomputer.com)
191.
Malicious Android apps on Google Play downloaded 42 million times
(bleepingcomputer.com)
192.
The Top 3 Browser Sandbox Threats That Slip Past Modern Security Tools
(bleepingcomputer.com)
193.
Fake Solidity VSCode extension on Open VSX backdoors developers
(bleepingcomputer.com)
194.
195.
Open VSX rotates access tokens used in supply-chain malware attack
(bleepingcomputer.com)
196.
NPM flooded with malicious packages downloaded more than 86k times
(news.ycombinator.com)
197.
Malicious NPM packages fetch infostealer for Windows, Linux, macOS
(bleepingcomputer.com)
198.
NPM flooded with malicious packages downloaded more than 86,000 times
(arstechnica.com)
199.
The security paradox of local LLMs
(news.ycombinator.com)
200.
CISA: High-severity Windows SMB flaw now exploited in attacks
(bleepingcomputer.com)
201.
Find hidden malicious OAuth apps in Microsoft 365 using Cazadora
(bleepingcomputer.com)
202.
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
(bleepingcomputer.com)
204.
Hackers can steal 2FA codes and private messages from Android phones
(arstechnica.com)
205.
206.
207.
First Malicious MCP in the Wild: The Postmark Backdoor Stealing Your Emails
(news.ycombinator.com)
208.
Microsoft Edge to block malicious sideloaded extensions
(bleepingcomputer.com)
209.
Malicious Rust packages on Crates.io steal crypto wallet keys
(bleepingcomputer.com)
210.
NPM package caught using QR Code to fetch cookie-stealing malware
(bleepingcomputer.com)