Over 1,000 exposed ComfyUI instances exploited via unauthenticated code execution, enabling Monero mining and botnet expansion.
IntroductionOn March 31, 2026, Anthropic accidentally exposed the full source code of Claude Code (its flagship ...
Anthropic is trying to remove details about its coding agent from GitHub, but programmers are converting the code into ...
An incident of LinkedIn malware means jobseekers and employers need to take more care with their applications and ...
Meta pauses Mercor partnership after a major data breach raises concerns over exposure of sensitive AI training data.
Or, why the software supply chain should be treated as critical infrastructure with guardrails built in at every layer.
North Korean hackers used an updated version of a known backdoor to target a popular npm package.
The maintainer account for the axios package on npm was compromised to inject a remote access trojan for Windows, macOS, and ...
M stolen after six-month DPRK social engineering campaign began fall 2025, exposing Drift’s contributors and cloud assets.
AI hiring startup Mercor confirmed it was "one of thousands of companies" affected by the LiteLLM supply-chain attack as the ...
A North Korea-nexus threat actor compromised the widely used axios npm package, delivering a cross-platform remote access ...
Meta has indefinitely paused work with $10B AI data startup Mercor after a LiteLLM supply chain attack exposed training ...