The repository reached the #1 trending position on Hugging Face within 18 hours, highlighting how public AI repositories are ...
The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows ...
Malicious Lightning 2.6.2/2.6.3 released April 30 enable credential theft via hidden payload, leading to PyPI quarantine and ...
A North Korean APT has crafted malicious software packages to appeal to AI coding agents, while ‘slopsquatting’ shows the ...
Fake OpenAI Privacy Filter hit #1 on Hugging Face with 244,000 downloads, spreading infostealer malware to Windows users.
New research exposes how prompt injection in AI agent frameworks can lead to remote code execution. Learn how these ...
Criminal hackers have used artificial intelligence to develop a working zero-day exploit, the first confirmed case of its ...
Hugging Face hosts 352,000 unsafe model issues. ClawHub's registry contains 341 malicious AI agent skills. The AI supply chain is now the most attractive target in software security.
A stealthy Python-based backdoor framework capable of long-term surveillance and credential theft has been identified ...
Companies are treating these repositories like content delivery networks - now the Linux Foundation and colleagues are saying ...
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via ...
Socket’s acquisition of Secure Annex extends software supply-chain security beyond open-source dependencies into browser and ...