-
North Korea–linked operators have quietly turned popular npm packages into a high‑volume access vector for developer and build environments, chaining multiple compromises of axios, debug, chalk, and typo‑crypto into a coordinated software supply‑chain …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GitLab has released security updates for both the Community Edition (CE) and Enterprise Edition (EE), addressing 13 vulnerabilities that could allow unauthorized data exposure, tampering with CI/CD pipelines, bypassing protected branches, and denial-of…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Node.js Project has released security updates for the active Node.js versions 22.x, 24.x, and 26.x, addressing 11 vulnerabilities. These vulnerabilities range from high-severity issues, such as HTTP/2 memory corruption and permission-bypass flaws, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent JavaScript backdoor, OWAReaper, that can survive credential rotation, browser restarts, and full hos…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Users of Claude experienced service disruptions on Wednesday when Anthropic reported elevated error rates across all Claude models. This incident affected the Claude.ai chatbot, the Claude API at api.anthropic.com, Claude Code, and Claude Cowork, preve…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Håkon Måløy has disclosed a cross-domain prompt injection vulnerability affecting Microsoft Copilot for Word. This vulnerability could allow malicious instructions hidden within documents to alter Copilot-generated content and sprea…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Tor Browser users on unpatched versions may be at risk of compromise simply by visiting a malicious webpage, following the disclosure of CVE-2026-10702, a serious vulnerability in Mozilla Firefox’s JavaScript engine. Security researchers at Nebula Secu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in Ruby on Rails’ Active Storage component could allow unauthenticated attackers to read arbitrary files on vulnerable application servers, potentially escalating to remote code execution. This vulnerability is tracked as…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to achieve full remote code execution (RCE) with a single HTTP request. This vulnerability, tracked as CVE-2026-59726 and…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Broadcom has released important security updates addressing critical vulnerabilities in VMware that could allow remote attackers to bypass vCenter authentication or execute arbitrary code. These vulnerabilities, outlined in advisory VMSA-2026-0006, aff…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


