Open source software with more than 1 million monthly downloads was compromised after a threat actor exploited a ...
VS Code extensions since Dec 21, 2025 fuel GlassWorm v2, installing cross-IDE malware and stealing credentials.
A coordinated relief effort to raise funds following Kelp DAO’s $290 million exploit this month crossed a critical threshold ...
An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive ...
A new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 "sleeper" extensions that turn malicious ...
An OpenSSH vulnerability introduced 15 years ago could allow attackers to obtain full root shell access to vulnerable servers ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results