Cybersecurity

Open VSX Bug Let Malicious Extensions Bypass Scans

A critical security flaw in the Open VSX registry's scanning pipeline could have allowed malicious extensions to bypass vetting checks.The bug, named Open Sesame,...

LangChain & LangGraph AI Frameworks Expose Sensitive Data

Three security vulnerabilities (CVE-2026-34070, CVE-2025-68664, CVE-2025-67644) were disclosed in LangChain and LangGraph frameworks, impacting over 84 million weekly downloads.The flaws could expose filesystem data,...

Claude Chrome Extension Vulnerability Patched

A critical flaw in the Anthropic Claude Chrome extension allowed websites to silently inject malicious prompts, compromising user security.The vulnerability combined an overly permissive...

Coruna iOS Exploit Kit Evolved From Triangulation

The recently uncovered iOS exploit kit Coruna uses an updated version of the kernel exploit framework from the 2023 Operation Triangulation espionage campaign.The framework...

GlassWorm Attack Steals Data Via Fake Chrome Extension

GlassWorm attackers now use a multi-stage framework that steals data and delivers a remote access trojan via a malicious Chrome extension.The malware employs the...

French Firms Targeted by Resume-Carrying Cryptomining Malware

A phishing campaign uses fake, obfuscated French-language resumes to deliver malware that mines cryptocurrency and steals data.The attack chain completes in just 25 seconds...

TeamPCP Attack Spreads From Trivy to Checkmarx Tools

Credential-stealing malware known as "TeamPCP Cloud stealer" has compromised GitHub Actions workflows from Checkmarx, following a similar attack on Aqua Security's Trivy scanner.The stealer...

Russian Hacker Jailed for Ransomware Attacks

Russian access broker Aleksei Volkov was sentenced to 6.75 years in U.S. prison for enabling ransomware attacks causing over $9 million in losses.U.S. prosecutors...

Latest news

Bank of Canada Study: Aave V3 Had Zero Bad Loans in 2024

A Bank of Canada staff analysis found Aave V3 had zero non-performing loans in 2024, protecting lenders.The overcollateralized, automated...

Tech Giants Found AI Payment Protocol Group

The x402 Foundation launched on Thursday by the Linux Foundation to govern an AI payment protocol, backed by tech...

Elliptic Links $286M Drift Protocol Hack to North Korea

Elliptic attributes the $286 million exploit of Drift Protocol to actors linked to North Korea (DPRK), marking the 18th...