241.
242.
Hackers breach Toptal GitHub account, publish malicious npm packages
(bleepingcomputer.com)
243.
Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware
(news.ycombinator.com)
244.
GitHub abused to distribute payloads on behalf of malware-as-a-service
(arstechnica.com)
245.
North Korean XORIndex malware hidden in 67 malicious npm packages
(bleepingcomputer.com)
246.
Beware! Research shows Gmail’s AI email summaries can be hacked
(androidauthority.com)
247.
Malicious VSCode extension in Cursor IDE led to $500K crypto theft
(bleepingcomputer.com)
248.
Google Gemini flaw hijacks email summaries for phishing
(bleepingcomputer.com)
249.
Malicious Chrome extensions with 1.7M installs found on Web Store
(bleepingcomputer.com)
250.
Dozens of fake wallet add-ons flood Firefox store to drain crypto
(bleepingcomputer.com)
251.
New FileFix attack runs JScript while bypassing Windows MoTW alerts
(bleepingcomputer.com)
252.
WinRAR patches bug letting malware launch from extracted archives
(bleepingcomputer.com)
253.
Show HN: VSCan - Detect Malicious VSCode Extensions
(news.ycombinator.com)
254.
SonicWall warns of trojanized NetExtender stealing VPN logins
(bleepingcomputer.com)
255.
256.
CoinMarketCap briefly hacked to drain crypto wallets via fake Web3 popup
(bleepingcomputer.com)
257.
Malicious AI swarms can threaten democracy
(news.ycombinator.com)
258.
259.
GitLab patches high severity account takeover, missing auth issues
(bleepingcomputer.com)
260.
Apiiro unveils free scanner to detect malicious code merges
(bleepingcomputer.com)
261.
UNC6384 Targets European Diplomatic Entities With Windows Exploit
(darkreading.com)