Two fake spellchecker packages on PyPI hid a Python RAT in dictionary files, activating malware on import in version 1.2.0.
This is Part 2 of our two-part technical analysis on the Gopher Strike and Sheet Attack campaigns. For details on the Gopher Strike campaign, go to Part 1.IntroductionIn September 2025, Zscaler ...
Marketplace that were collectively installed 1.5 million times, exfiltrate developer data to China-based servers.
Two VSCode extensions are harvesting sensitive data and sending it to China.
A new malicious campaign mixes the ClickFix method with fake CAPTCHA and a signed Microsoft Application Virtualization (App-V ...
Security researchers found two AI-branded VS Code extensions with 1.5M installs that covertly send source code and files to ...
Two malware campaigns weaponize open-source software to target executives and cloud systems, combining social engineering ...
A comprehensive SAML development guide for engineering leaders. Learn about assertions, metadata, and securing single sign-on for enterprise CIAM.
Some attachments in Epstein emails can be recovered unredacted, because base64-encoded email attachment data was included in the DOJ releases.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results