CVE Lite CLI
CVE Lite CLI is a free, open-source command line tool that scans projects in seconds to find and fix vulnerable dependencies in JavaScript and Typescript files.
HalluSquatting is an attack where researchers pre-compute fake repository, package, or skill names that AI coding agents predictably invent, register those names first, and load them with malicious instructions.
CVE Lite CLI is a free, open-source command line tool that scans projects in seconds to find and fix vulnerable dependencies in JavaScript and Typescript files.
Anthropic's Project Glasswing program has expanded to 150 organizations in 15 countries, discovering over 10,000 high-severity software vulnerabilities since its launch in April.
Department of Homeland Security Secretary Markwayne Mullin says CISA ideally needs 2,800 personnel to effectively carry out its cybersecurity mission.
The Trump administration is considering Shyam Sankar, a Palantir executive, to lead the Cybersecurity and Infrastructure Security Agency (CISA).
A new supply-chain attack has infected 36 packages on the Node Package Manager with IronWorm malware, targeting environment variables and credential files.
The United Nations' World Food Programme disclosed a breach affecting 600,000 Gaza households, with attackers gaining access to personal data including names, ID numbers, and location information.
The FTC is considering modifying or setting aside a $150 million privacy penalty against X, formerly Twitter, for using account security data to support targeted advertising.
A public dispute between Microsoft and a security researcher has reignited debate over vulnerability disclosure, with some experts arguing that the company's response was overly aggressive and harmed trust with the research community.
Chinese espionage group UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD.