Skip to content
Tech News
clear
Topics: Today This Week This Month This Year
1.
Malicious JetBrains Marketplace plugins steal AI API keys from developers (bleepingcomputer.com)
2.
Arch Linux Malware Incident: Malicious Commits Found in 1,579 Packages (slashdot.org)
3.
AUR packages compromised with Infostealer and Rootkit (news.ycombinator.com)
4.
Malicious npm packages detected across Red Hat Cloud Services (news.ycombinator.com)
5.
After fixing a family friend’s phone, I realized Google Play Protect is not doing enough (androidauthority.com)
6.
GrapheneOS closes an Android VPN loophole before Google does (Updated: Google statement) (androidauthority.com)
7.
Compromised Mistral AI and TanStack packages may have exposed GitHub, cloud and CI/CD credentials in 'mini Shai Hulud' malware infection — supply-chain campaign spreads across npm and AI developer ecosystems like wildfire (tomshardware.com)
8.
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain (darkreading.com)
9.
RedSun: System user access on Win 11/10 and Server with the April 2026 Update (news.ycombinator.com)
10.
Popular WordPress plugins backdoored after ownership change, putting thousands of websites at risk (techspot.com)
11.
Bad influence: LLMs can transmit malicious traits using hidden signals (feeds.nature.com)
12.
Malware campaign lures users with fake Windows Update website (techspot.com)
13.
A new spam policy for “back button hijacking” (news.ycombinator.com)
14.
A new spam policy for "back button hijacking" (news.ycombinator.com)
15.
Popular Musician Loses Life Savings Through Malicious Crypto Wallet in Apple’s App Store (gizmodo.com)
16.
How to Find Out Whether Your Computer Is Part of a Botnet—and What to Do About It (feeds.content.dowjones.io)
17.
Residential proxies evaded IP reputation checks in 78% of 4B sessions (bleepingcomputer.com)
18.
TikTok for Business accounts targeted in new phishing campaign (bleepingcomputer.com)
19.
Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised (news.ycombinator.com)
20.
New font-rendering trick hides malicious commands from AI tools (bleepingcomputer.com)
21.
Xygeni GitHub Action Compromised Via Tag Poison (darkreading.com)
22.
This high-severity Chrome Gemini vulnerability lets malicious extensions spy on your PC (zdnet.com)
23.
Why the shift left dream has become a nightmare for security and developers (bleepingcomputer.com)
24.
Supply Chain Attack Secretly Installs OpenClaw for Cline Users (darkreading.com)
25.
Google says its AI systems helped deter Play Store malware in 2025 (techcrunch.com)
26.
CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups (bleepingcomputer.com)
27.
Fake job recruiters hide malware in developer coding challenges (bleepingcomputer.com)
28.
Claude LLM artifacts abused to push Mac infostealers in ClickFix attack (bleepingcomputer.com)
29.
Microsoft: New Windows LNK spoofing issues aren't vulnerabilities (bleepingcomputer.com)
30.
Unofficial 7-zip.com website served up malware-laden downloads for over a week — infected PCs forced into a proxy botnet (tomshardware.com)
Today's top topics: apple google anthropic openai amazon android authority nasa nvidia china spacex
View all today's topics →