IBM and Red Hat launch Lightwell to defend open-source code from AI attacks ...
Stolen and leaked credentials lead to Node.js packages from AsyncAPI and Jscrambler Code Integrity being poisoned with ...
A newly-disclosed exploit in Claude Code’s ‘auto-mode’ leaves developers facing remote code execution (RCE) vulnerabilities ...
Artificial intelligence company OpenAI has confirmed that the mystery attacker behind last week's Hugging Face breach was two ...
Chrome Firefox security update July 2026 delivered emergency patches across five vendors on July 15: Mozilla confirmed public ...
Zimbra zero-click vulnerability CVE-2025-66376 is being actively exploited by Russian hackers targeting NATO governments and defense contractors. Unit 42 and CISA warn that Void Blizzard has raided ...
Capital One has open-sourced VulnHunter, an AI security tool that finds exploitable code flaws, maps attack paths and helps developers fix vulnerabilities faster.
Community-run Swift package search engine and metadata index Swift Package Index is joining Apple, but says little is changing for developers in the near term. Here are the details. Most Swift ...
Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and ...
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain ...
Security researchers caught hackers trying to plant a backdoor inside the Injective npm package — a widely used tool in ...
The Swift Package Index is no longer independent as Apple has taken control, but it will remain an open source search engine for third-party code. The Swift Package Index gave developers one trusted ...