WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
A trojanized QuickFox Windows installer delivered FDMTP in a supply chain attack active since at least August 2025, after ...
JavaScript向けパッケージ管理サービス「npm」で、広く使われている数百個のパッケージに認証情報を盗むマルウェアが混入される大規模なサプライチェーン攻撃が発生しました。セキュリティ企業のAikido ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
QuickFox VPN users might be at risk. Researchers discovered that attackers trojanized the software's Windows installer for ...
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
FortiGuard exposes year-long QuickFox VPN supply chain attack deploying FDMTP implant on corporate Windows machines only.
Hundreds of NPM packages have been hit in a massive supply chain attack. The Shai-Hulud worm variant is stealing developer ...
The popular key-value database keyv and other widely used npm packages were targeted in a supply chain attack. The potential ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.