GitHub links repo breach to TanStack npm supply-chain attack
GitHub links repo breach to TanStack npm supply-chain attack By Sergiu Gatlan May 21, 2026 02:54 AM GitHub says the hackers who breached 3,800 internal repositories gained access via…
GitHub links repo breach to TanStack npm supply-chain attack By Sergiu Gatlan May 21, 2026 02:54 AM GitHub says the hackers who breached 3,800 internal repositories gained access via…
Critical Kirki flaw exploited to hijack WordPress admin accounts By Bill Toulas June 2, 2026 06:12 PM Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki…
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages By Bill Toulas June 8, 2026 04:41 PM Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of…
Hackers compromise 14,500 Dahua web cameras in 35-day campaign By Bill Toulas August 19, 2026 02:09 PM In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more…
VS Code zero-day lets hackers steal GitHub tokens in one click By Sergiu Gatlan June 3, 2026 02:50 AM A security researcher has released exploit code for a Visual Studio…
WP Maps Pro bug exploited to create admin accounts on WordPress sites By Bill Toulas May 31, 2026 10:06 AM Hackers are targeting WordPress websites running a vulnerable version of the…
OptinMonster WordPress plugin hacked in CDN supply-chain attack By Bill Toulas June 15, 2026 01:37 PM WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack…
Hackers breached a small Polish energy plant via private APN last year By Bill Toulas August 10, 2026 07:07 PM Hackers used a dedicated mobile gateway to compromise a second facility…
…According to the report, the attacker added a post-install script to invoke npm and retrieve the malicious package. "The modified packages add a post-install script that invokes npm and installs…
SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released…