Please turn on your JavaScript for this page to function normally.
Social engineering attacks on open source developers are escalating
North Korean hackers spent weeks socially engineering an Axios maintainer through a fake Slack workspace, a cloned company identity, and a fabricated Microsoft Teams call that …
Self-spreading npm malware targets developers in new supply chain attack
Security researchers have uncovered another supply chain attack targeting developers: 19 typosquatting npm packages published on npmjs.com that steal credentials, infect …
Fake browser crash alerts turn Chrome extension into enterprise backdoor
Browser extensions are a high-risk attack vector for enterprises, allowing threat actors to bypass traditional security controls and gain a foothold on corporate endpoints. …
Featured news
Resources
Don't miss
- DarkMe RAT trades zero-days for plain phishing emails
- Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
- Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
- Prismor: Open-source runtime control plane for AI agents
- Product showcase: Scamwise checks the red flags before you take the bait