The Shai-Hulud supply-chain malware campaign is exploiting the automated systems developers trust to publish software safely.
Thirteen critical vulnerabilities have been found in the vm2 JavaScript sandbox package that could allow an attacker’s code ...
The world’s largest open-source registry, node package manager (npm), has been hit by another fast-moving malware attack, ...
Morning Overview on MSN
OpenAI asks all macOS users to update immediately after the TanStack attack forced the company to rotate its code-signing certificates
OpenAI is telling every Mac user running its ChatGPT or Codex desktop app to update right now. The urgency traces back to a ...
Socket is scaling to defend open source against supply chain attacks as AI accelerates software development. SAN ...
OpenAI confirmed on Wednesday that it found no evidence suggesting user data was compromised following a security incident ...
Researchers say the campaign uses a browser-based JavaScript VM to hide credential theft and intercept MFA at scale.
Merck (NYSE: MRK), known as MSD outside of the United States and Canada, today announced the pivotal Phase 3 TroFuse-005 trial evaluating sacituzumab tirumotecan (sac-TMT), an investigational ...
TanStack has released a detailed postmortem describing a sophisticated supply-chain attack that compromised 42 npm packages ...
Over 170 TanStack, Mistral AI, OpenSearch, UiPath, and other packages were affected in a new Mini Shai-Hulud supply chain ...
Cohere, the trusted sovereign AI platform for governments and regulated industries worldwide, today announced the release of Command A+, a powerful open-source Mixture-of-Experts (MoE) model released ...
Socket raises $60M to expand AI-driven software supply chain security and protect developers from cyber threats worldwide.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results