Malicious JetBrains Marketplace plugins steal AI API keys from developers
(bleepingcomputer.com)
1.
2.
3.
AUR packages compromised with Infostealer and Rootkit
(news.ycombinator.com)
4.
Malicious npm packages detected across Red Hat Cloud Services
(news.ycombinator.com)
5.
After fixing a family friend’s phone, I realized Google Play Protect is not doing enough
(androidauthority.com)
6.
GrapheneOS closes an Android VPN loophole before Google does (Updated: Google statement)
(androidauthority.com)
8.
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain
(darkreading.com)
9.
RedSun: System user access on Win 11/10 and Server with the April 2026 Update
(news.ycombinator.com)
10.
11.
Bad influence: LLMs can transmit malicious traits using hidden signals
(feeds.nature.com)
12.
13.
A new spam policy for “back button hijacking”
(news.ycombinator.com)
14.
A new spam policy for "back button hijacking"
(news.ycombinator.com)
15.
16.
How to Find Out Whether Your Computer Is Part of a Botnet—and What to Do About It
(feeds.content.dowjones.io)
17.
Residential proxies evaded IP reputation checks in 78% of 4B sessions
(bleepingcomputer.com)
18.
TikTok for Business accounts targeted in new phishing campaign
(bleepingcomputer.com)
19.
Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
(news.ycombinator.com)
20.
New font-rendering trick hides malicious commands from AI tools
(bleepingcomputer.com)
21.
Xygeni GitHub Action Compromised Via Tag Poison
(darkreading.com)
22.
23.
Why the shift left dream has become a nightmare for security and developers
(bleepingcomputer.com)
24.
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
(darkreading.com)
25.
Google says its AI systems helped deter Play Store malware in 2025
(techcrunch.com)
26.
CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups
(bleepingcomputer.com)
27.
Fake job recruiters hide malware in developer coding challenges
(bleepingcomputer.com)
28.
Claude LLM artifacts abused to push Mac infostealers in ClickFix attack
(bleepingcomputer.com)
29.
Microsoft: New Windows LNK spoofing issues aren't vulnerabilities
(bleepingcomputer.com)