Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites ...
Threat actors are exploiting CVE-2026-58138, a critical-severity remote code execution vulnerability in Orkes Conductor.
Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.
GitHub's npm registry shipped staged publishing in May 2026, the first mandatory 2FA human checkpoint in its 16-year history, ...
Hackers used a malicious worker to inject scripts into more than 100,000 websites via the Brevo supply chain attack.
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component ...
OpenAI fixed two Codex sandbox escape vulnerabilities after researchers showed how malicious code could bypass key security restrictions.
SlowMist confirms an active iOS exploit that steals crypto private keys via Safari, affecting iPhones running iOS 13 through 26.5.
Malicious JavaScript campaigns on e-commerce storefronts evaded VirusTotal in 7 of 8 cases, exposing a structural gap in signature-based scanning. Cloudflare's graph neural network caught all eight ...
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The ...
WordPress Click2Shell vulnerability lets attackers silently install themes on any admin’s site via a single crafted link, ...
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.