Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry ...
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by ...
On 11 July, Hugging Face was subjected to an intense cyberattack from a then-unknown actor. The speed and coordination of the ...
If that answer seems a little anticlimactic, wait until you’ve seen DoomPaint in action before you scoff. Its creator, ...
DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the ...
Malicious npm packages impersonate Alibaba tools to deliver a cross-platform RAT with command execution, persistence, and ...
At Black Hat USA, Zenity Labs today announced new research detailing an active credential-stealing malicious skills campaign distributed through Vercel's skills.sh. The affected skill family amassed ...
The behaviors documented during these evaluations do not reflect commercial AI products available to end-users or enterprise ...
As AI agents gain autonomy inside enterprises, the biggest cybersecurity threat may no longer be hackers, but the agents ...
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox at Black Hat USA 2026.
Max, its most powerful AI model with 2.4 trillion parameters, intensifying competition in China’s AI race. The model ...
TripGain MCP Server launches at GBTA Convention 2026, extending agentic AI beyond flight booking to handle employee expense ...