Treat this as an immediate security incident, CISOs advised; researchers say it’s one of the most sophisticated supply chain ...
The latest releases of Cursor and Windsurf integrated development environments are vulnerable to more than 94 known and ...
Security researcher Eaton Zveare discovered that two sets of Amazon Web Services keys were left exposed across Tata Motors' ...
The timing of the Octoverse 2025 report release during the conference proved strategic, as it provided attendees with ...
The Open VSX registry rotated access tokens after they were accidentally leaked by developers in public repositories and ...
Researchers at tech giant Google's Threat Intelligence team highlight a years-old exploit that is now being used by North Korean state-sanctioned hackers.
A Sonatype report reveals a sharp rise in sophisticated attacks hiding in trusted code libraries, with data theft becoming the primary goal ...
Supply chain security company Safety has discovered a trojan in NPM that masqueraded as Anthropic’s popular Claude Code AI ...
In the major release, the browser mode is stable, which recently offers Visual Regression Testing to uncover optical changes.
There isn’t a consistent threat model for extension marketplaces yet, McCarthy said, making it difficult for any platform to anticipate these risks. However, he added, Microsoft’s marketplace has seen ...
Web exposure management platform startup Reflectiz Ltd. revealed today that it has raised $22 million in new funding to ...