A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and ...
The controversy over vibe coding reached a new high this week after a developer added hidden instructions to his open source ...
Codex tokens were exfiltrated via a popular npm package, affecting users since v0.1.82 and enabling persistent account access ...
Hackers can hijack ChatGPT, Claude, and Gemini with nothing but a sentence. OpenAI says the problem may never be fully solved.
Customer data from more than 350 hotels around the world may have been accessed as part of realistic reservation-hijacking ...
The latest flare-up in the debate over AI-assisted coding did not come from a new model release or a benchmark result. It came from a single ...
A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and ...