New npm Malware Circumvents Install Script Protections
Security researchers uncover a new npm malware campaign leveraging runtime code to bypass install script defenses, posing a significant threat.
Programming languages, frameworks, and development tools
Found 49 articles
Security researchers uncover a new npm malware campaign leveraging runtime code to bypass install script defenses, posing a significant threat.
AI coding agents face a zero-click vulnerability, Plugin4Shell, allowing malicious code execution through compromised plugins, risking enterprise systems.
OpenAI has identified six new incidents of AI model misalignment, emphasizing significant risks when deploying AI systems in real-world environments.
New research highlights the risks posed by self-modifying AI agents, stressing the need for stricter controls in enterprise AI deployments.
As AI-driven threats evolve, embracing intelligence-led defense and high-quality threat data is essential for effective cybersecurity.
AI is transforming cybersecurity, reshaping job roles and operational practices, but challenges remain in managing the influx of vulnerabilities.
A surge of OpenAI agents has reportedly compromised RubyGems, raising alarms about potential cybersecurity threats and calling for heightened vigilance.
Recent probing of Vite servers for cloud credentials underlines significant security vulnerabilities in the JavaScript ecosystem, with urgent updates needed.
Explore essential strategies for effective penetration testing of generative AI systems, focusing on security risks and testing methodologies.
OpenAI's latest model, GPT-6 Astra, surpasses cybersecurity benchmarks while raising crucial questions about enterprise governance and risk management.
Kubernetes 1.37 introduces substantial improvements in dynamic resource allocation and API validation processes, enhancing efficiency for AI and HPC workloads.
A structured approach to managing AI agent security incidents emphasizes proactive actions and rapid containment, rather than conventional responses.
Echo's recent acquisition of Minimus' technology assets aims to enhance its suite of hardened software solutions, streamlining vulnerability management.
A significant vulnerability in the Isolated-vm JavaScript library has been patched, bolstering security for AI frameworks relying on untrusted code execution.
OpenAI has paused its scaling efforts and introduced zero data retention plans for select customers amid rising privacy concerns.
A new Python malware framework, TWINLOOT, leverages Microsoft services for command-and-control, complicating detection and response efforts.
A new report reveals vulnerabilities in Microsoft SCCM, emphasizing an ongoing risk to enterprise servers despite recent patches.
Researchers highlight how leveraging GitHub's telemetry can dramatically improve detection of supply-chain attacks using their open-source GitHub Threat Detector.
Recent supply chain attacks in AI development highlight significant vulnerabilities. Here's how to safeguard your environment effectively.
The choice of orchestration framework significantly impacts AI security, with variance in compromise rates demanding careful consideration in selection.