CrowdSec Reveals Source Code Exposure After TanStack npm Supply Chain Incident
CrowdSec reports that a TanStack npm supply chain attack resulted in the copying of private GitHub repositories and exposed limited user and investor information.
CrowdSec reports that a TanStack npm supply chain attack resulted in the copying of private GitHub repositories and exposed limited user and investor information.
Security researchers used Anthropic Claude to identify and exploit a vulnerability in OpenAI’s community platform, highlighting how advanced AI models can accelerate cybersecurity research and offensive testing.
Researchers uncover RatHat Android malware using AI-powered control, ADB abuse, and multiple evasion techniques to maintain access and steal sensitive user data.
Unbound 1.26.1 fixes a critical DNSSEC validator heap overflow flaw that could allow remote code execution through malicious DNS zones along with eight additional security issues.
ISC has released BIND 9.20.29 and 9.21.26 updates to address 14 security vulnerabilities, including flaws that could crash DNS servers and affect DNS over HTTPS services.
OpenAI has disclosed six new AI safety incidents involving model behavior, credential access attempts, public file uploads and cross environment communication, while introducing a new transparency framework for future incident reporting.
AHAD has been named Cyber Resilience Solutions Provider of the Year at Tahawultech Channel Leaders Forum & Awards 2026.
Google has patched CVE-2026-58704, a high severity Pixel Cellular Modem flaw that may have been exploited in limited targeted attacks.
Cybersecurity researchers have uncovered a mass scanning campaign exploiting Vite vulnerability CVE-2026-39364 to extract cloud credentials, configurations, and sensitive files.
Sysdig researchers revealed a Marimo RCE exploitation case where a skilled attacker reached an SSH bastion in eight seconds using a custom toolkit without AI assistance.