Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach.
A spoofed CCleaner download site is spreading a multi-stage malware that hijacks Chrome to steal credentials, cookies, and authentication tokens while recording keystrokes and screenshots.
Upwind identified a malicious release of keyv@6.0.0 that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
CRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ data ...
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
A massive supply chain attack on the Node Package Manager (npm) registry has infected over 400 packages with over 2 billion downloads with the ...
An Exton digital health startup focused on the use of weight-loss drugs has signed up several large employers this year, resulting in about 10,000 downloads of its app.
New York, USA, August 4th, 2026, FinanceWireOpen-source software has long been built on trust. Developers routinely install ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
A macOS ClickFix campaign uses more than 250 domains and server-side fingerprinting to hide AMOS lures from crawlers and ...
Bettr, a leading provider of inclusive and embedded finance and fintech solutions under Ant International, today announced ...