Cybersecurity

Open VSX Bug Let Malicious Extensions Bypass Scans

A critical security flaw in the Open VSX registry's scanning pipeline could have allowed malicious extensions to bypass vetting checks.The bug, named Open Sesame,...

LangChain & LangGraph AI Frameworks Expose Sensitive Data

Three security vulnerabilities (CVE-2026-34070, CVE-2025-68664, CVE-2025-67644) were disclosed in LangChain and LangGraph frameworks, impacting over 84 million weekly downloads.The flaws could expose filesystem data,...

Claude Chrome Extension Vulnerability Patched

A critical flaw in the Anthropic Claude Chrome extension allowed websites to silently inject malicious prompts, compromising user security.The vulnerability combined an overly permissive...

Coruna iOS Exploit Kit Evolved From Triangulation

The recently uncovered iOS exploit kit Coruna uses an updated version of the kernel exploit framework from the 2023 Operation Triangulation espionage campaign.The framework...

GlassWorm Attack Steals Data Via Fake Chrome Extension

GlassWorm attackers now use a multi-stage framework that steals data and delivers a remote access trojan via a malicious Chrome extension.The malware employs the...

French Firms Targeted by Resume-Carrying Cryptomining Malware

A phishing campaign uses fake, obfuscated French-language resumes to deliver malware that mines cryptocurrency and steals data.The attack chain completes in just 25 seconds...

TeamPCP Attack Spreads From Trivy to Checkmarx Tools

Credential-stealing malware known as "TeamPCP Cloud stealer" has compromised GitHub Actions workflows from Checkmarx, following a similar attack on Aqua Security's Trivy scanner.The stealer...

Russian Hacker Jailed for Ransomware Attacks

Russian access broker Aleksei Volkov was sentenced to 6.75 years in U.S. prison for enabling ransomware attacks causing over $9 million in losses.U.S. prosecutors...

Latest news

PayPal Down 13% as Advent, Stripe Drop Bid; Retail Bullish

Paypal stock plunged nearly 13% last week after reports that Advent and Stripe abandoned their takeover attempt.Retail investors remain...

Polygon Labs quietly fixes critical security bugs with hard forks

Polygon Labs disclosed it patched a batch of security vulnerabilities through two hard forks — Austin on its Bor...

Saylor Signals ‘We’re Back’ as Strategy Set to Resume Bitcoin Buys

Strategy co-founder Michael Saylor posted a cryptic message on X, signaling the company's likely return to Bitcoin buying.Saylor has...