Malicious telnyx 4.87.1/4.87.2 on PyPI used audio steganography March 27, 2026, enabling cross-platform credential theft.
Attackers weaponized critical RCE within hours, prompting CISA to add the flaw to its KEV catalog and set an urgent patch ...
A threat actor who stole credentials from a legitimate node package manager (npm) publisher has spread a persistent, ...
During a recent penetration test, we came across an AI-powered desktop application that acted as a bridge between Claude ...
Langflow CVE-2026-33017 exploited in 20 hours after disclosure, enabling RCE via exec(), exposing systems before patching ...
The primary condition for use is the technical readiness of an organization’s hardware and sandbox environment.
I’ve used plenty, but this one rewired my daily workflow.
An N-day vulnerability in Microsoft Word exposes nearly 14 million assets. Attackers can exploit this flaw to bypass security ...
LiteLLM, a massively popular Python library, was compromised via a supply chain attack, resulting in the delivery of ...
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
OpenAI announced they are extending the Responses API to make it easier for developer to build agentic workflows, adding ...