Zoom Zero-Click RCE: AI Helped Build an Exploit in Under 24 Hours
A critical Zoom vulnerability chain could have allowed an attacker to take control of another participant’s device simply by joining...
A critical Zoom vulnerability chain could have allowed an attacker to take control of another participant’s device simply by joining...
Ravie LakshmananAug 11, 2026Supply Chain Attack / Vulnerability Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin...
The Hacker NewsAug 10, 2026Software Supply Chain / DevSecOps AI is helping development teams produce far more code, far faster....
Swati KhandelwalAug 01, 2026Web Security / Supply Chain Attack Attackers modified a JavaScript file served by advertising technology company Adform,...
Ravie LakshmananJul 27, 2026Software Supply Chain / DevSecOps GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool...
Ravie LakshmananJul 22, 2026Supply Chain Attack / Malware Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing...
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems...
Ravie LakshmananJul 17, 2026Software Supply Chain / Malware Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting...
The Hacker NewsJul 15, 2026Web Security / Supply Chain Security A single approved marketing tag can quietly load fourth-party code...
Ravie LakshmananJul 10, 2026Software Supply Chain / Malware Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and...
Ravie LakshmananJul 09, 2026Developer Security / Supply Chain Security Datadog Security Labs is warning of "several overlapping campaigns" that are...
Ravie LakshmananJul 09, 2026Supply Chain Security / DevSecOps GitHub has officially announced the release of npm version 12 with install...
The Hacker NewsJul 07, 2026AI Security / Software Supply Chain Software supply chain security was hard enough. Then AI joined...
Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver...
Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades...