Open VSX removed three extension IDs from its malicious-extension list between August 16 and August 20, restoring publishing ...
Modern AI agents have become a new supply chain layer and how cybercriminals are exploiting the gap between the chain of ...
Malicious npm packages hide a Linux backdoor in calendar tools, using legitimate date functions to deliver RedShell into ...
A critical isolated-vm flaw lets untrusted JavaScript escape the V8 sandbox and potentially hijack the host process.
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. A critical-severity type ...
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability.
The type confusion vulnerability allows a guest-to-host sandbox escape which can lead to remote code execution ...
Isolated-vm's ExternalCopy type confusion lets sandboxed code corrupt host memory and potentially reach host RCE; fixes are ...
A newly disclosed critical vulnerabilities across several open-source SAML implementations through an AI-assisted research pipeline using Anthropic’s Claude Opus.
Firefox extensions pose as Web3 products to steal recovery phrases, private keys, keyrings, credentials, and clipboard data.
The criminal AI service uses jailbreaks to bypass safeguards on legitimate AI models and offers capabilities including ...