
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs…
LEER →
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs…
LEER →
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.…
LEER →
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via…
LEER →
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial…
LEER →
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root…
LEER →
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in…
LEER →
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change…
LEER →
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known…
LEER →
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in…
LEER →
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one…
LEER →