Thumbnail 1738346
thumbnail
Large (256x256)

Articles

One of JavaScript's most popular libraries compromised by hackers — Axios npm package hit in supply chain attack that deployed a cross-platform RAT
An attacker compromised the npm account of a lead Axios maintainer on March 30, and used it to publish two malicious versions of the widely used JavaScript HTTP client library.
AI cloud company Vercel breached after employee grants AI tool unrestricted access to Google Workspace — hacker seeking $2 million for stolen data
The breach exposed non-sensitive environment variables, and a threat actor operating under the ShinyHunters name has claimed responsibility.
1