PamDOORa Linux backdoor abuses PAM modules for SSH persistence and credential theft, increasing Linux server compromise risks ...
A fake repo impersonating the OpenAI Privacy Filter model racked up 244,000 downloads in under 18 hours before Hugging Face ...
CVE-2026-41940 exploitation by 2,000 IPs enabled Filemanager backdoor attacks, causing credential theft and persistent access ...
The PCPJack worm targets cloud environments and vulnerable web applications to remove TeamPCP infections and steal ...
An attacker poisoned 84 TanStack npm versions across 42 packages, stealing GitHub OIDC tokens and cloud keys while planting a ...
Four npm packages linked to SAP's Cloud Application Programming Model were hijacked. The hackers added code that steals ...
The terminal is fine. But if you actually want to live in your Hermes agent, here are the four best GUIs the community has ...
The popular Python package for monitoring data quality was briefly available as a malicious version. Provider Elementary ...
The stealthy Python-based backdoor framework deploys a persistent Windows implant likely designed for espionage.
Open source software with more than 1 million monthly downloads was compromised after a threat actor exploited a vulnerability in the developers’ account workflow that gave access to its signing keys ...
A new malware framework called PCPJack is stealing credentials from exposed cloud infrastructure while actively removing ...
A stealthy Python-based backdoor framework capable of long-term surveillance and credential theft has been identified ...