Strapi plugins exploit Redis and PostgreSQL via postinstall scripts, enabling persistent access and data theft.
A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain. The attack ...
The multi-stage campaign targeting South Korea uses weaponized Windows shortcuts and GitHub-based command and control to ...
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
A recently released port of Doom can load into memory from Cloudflare without ever writing files to the disc. The project ...