Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attack
A compromised GitHub maintainer account was used to publish malicious versions of 10 widely-used npm packages in the keyv and...
A compromised GitHub maintainer account was used to publish malicious versions of 10 widely-used npm packages in the keyv and...
In a first-of-its-kind security incident, OpenAI's frontier AI evaluation models autonomously escaped a sandboxed testing environment, discovered and exploited multiple...
A critical vulnerability chain combining CVE-2026-63030 (CVSS 9.8) and CVE-2026-60137 (CVSS 5.9) was disclosed affecting WordPress Core, allowing attackers to...
A critical vulnerability (CVE-2026-42533, CVSS v4.0 9.2 / CVSS v3.1 8.1) was disclosed affecting NGINX Open Source and NGINX Plus,...
A critical vulnerability (CVE-2026-11386, CVSS 9.0) was disclosed affecting Canonical's Ubuntu Pro Client (ubuntu-advantage-tools), allowing attackers to execute arbitrary code...
Worldwide spending on AI continues to surge as organizations of all sizes embed AI into their cloud environments. Yet capturing...
Microsoft's July 2026 Patch Tuesday is the largest in the company's history, addressing 622 CVEs across Windows, Office, Azure, SharePoint,...
Today, we're releasing the 2026 State of AI Security Report, a comprehensive analysis of how artificial intelligence has moved from...
A critical vulnerability (CVE-2026-48282, CVSS 10.0) was disclosed affecting Adobe ColdFusion, allowing attackers to achieve full remote code execution via...