77 Open VSX extensions found harvesting developer info
Counterfeit Open VSX Extensions Harvest Developer and CI/CD Environment InformationThe discovery of 77 counterfeit extensions on the Open VSX marketplace demonstrates how attackers can exploit developer trust without im…
Aug 05, 2026
New XCSSET variant targets macOS devs via compromised Xcode projects
New XCSSET Variant Turns Compromised Xcode Projects into a macOS Supply-Chain AttackThe emergence of XCSSET version 40 demonstrates how attackers are increasingly targeting software developers and the trusted developmen…
Aug 05, 2026
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA Adds Actively Exploited N-able, Apache Tomcat and Langflow Vulnerabilities to KEV CatalogThe addition of three vulnerabilities affecting N-able N-central, Apache Tomcat and IBM Langflow to CISA’s Known Exploited Vu…
Aug 05, 2026
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
Greatness Phishing Service Exploits RingCentral Trust to Compromise Microsoft 365 AccountsA phishing campaign impersonating RingCentral demonstrates how attackers can turn an organization’s trusted-vendor configurations…
Aug 05, 2026
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Fake Adobe and Zoom Updates Show How Attackers Abuse Trusted Software to Establish Persistent Remote AccessA series of phishing campaigns using fake Adobe Reader, Zoom, Microsoft Teams and Google Meet updates demonstrat…
Aug 04, 2026
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Keyv-Linked npm Worm Demonstrates How Developer Credentials Can Turn One Compromise into a Software Supply-Chain EpidemicThe discovery of a self-propagating npm worm linked initially to the popular Keyv package demonstr…
Aug 04, 2026
New DOUBLECUP ClickFix service hides malware in browser cache images
DOUBLECUP ClickFix Service Shows How Browser Caches Are Being Turned into Malware Delivery ChannelsThe newly identified DOUBLECUP loader-as-a-service demonstrates how cybercriminals are making ClickFix attacks more scal…
Aug 04, 2026
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
Critical cPanel Flaw Could Allow Hosting Customers to Execute SQL with Database Root PrivilegesA newly disclosed critical vulnerability in cPanel and WebHost Manager demonstrates the significant risks created when hosti…
Aug 04, 2026
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Malicious npm Packages Target Alibaba Developers with a Cross-Platform Remote-Access TrojanThe discovery of 18 malicious npm packages targeting users of Alibaba developer tools demonstrates how software supply-chain att…
Aug 04, 2026
Everside Health Data Breach Exposes Social Security Numbers
Everside Health Data Breach Highlights the Risks of Healthcare Information Stored with Third-Party VendorsThe data breach affecting Everside Health demonstrates how an organization’s cybersecurity exposure extends beyon…
Aug 03, 2026
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
INC Ransomware Exploitation of SonicWall SMA 1000 Flaws Shows Why VPN Appliances Must Be Treated as Critical Security InfrastructureThe emergence of INC Ransomware as the dominant threat actor exploiting vulnerabilities…
Aug 03, 2026
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
ExfilSquad Leak of UK Police Personnel Data Creates Serious Phishing and Officer-Safety RisksThe reported publication of information linked to more than 100,000 UK police officers and staff demonstrates how a data breac…
Aug 03, 2026