PAN-OS, the software behind Palo Alto Networks’ firewalls, is getting a major update. PAN-OS 12.2 Ceres focuses on proactively protecting software through ...
Amazon Threat Intelligence has tied a DPRK hacking group to four separate npm package supply chain attacks, including axios. The company’s security teams have connected the axios, debug, chalk, and ...
Upwind identified a malicious release of keyv@6.0.0 that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
For the third year in a row, prompt injection tops the OWASP GenAI / LLM Top Ten list issued today as being the most ...
AI models are finding thousands of zero-day flaws in minutes, forcing defenders to adopt automated, real-time virtual ...
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
A trojanized QuickFox Windows installer delivered FDMTP in a supply chain attack active since at least August 2025, after ...
A leaked n8n API key is only the start. GitGuardian's research traces the full chain, from exposed tokens and weak keys to ...
Security researchers at Kaspersky have uncovered technical evidence linking the massive supply chain attack on the popular ...
Application security has become one of the most important areas in modern software development. Companies no longer ...