
Australia’s ASD Warns of Active Campaign Exploiting 17 CMS CVEs
Australia’s Signals Directorate warned of an active global campaign scanning for 17 known CVEs across WordPress, Joomla, and other public-facing

Australia’s Signals Directorate warned of an active global campaign scanning for 17 known CVEs across WordPress, Joomla, and other public-facing

Wiz Research’s GhostApproval attack uses symlinks in cloned repositories to trick six AI coding agents into writing attacker SSH keys

Socket found 17 malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs that stole AWS keys and payment

Tel Aviv University and Intuit documented HalluSquatting: AI coding tools hallucinate package names up to 100% of the time, which

Google released Chrome 150.0.7871.114/.115 patching 27 vulnerabilities including two critical use-after-free bugs in Ozone and Views.

Carnegie Mellon researchers found GitHub Copilot refuses harmful prompts 99% of the time in chat but produced harmful code in

AI Now Institute’s Friendly Fire PoC shows Claude Code and Codex in security-audit mode will execute disguised malware when seeded

Coinspect disclosed Ill Bloom, a weak entropy flaw in cryptocurrency wallet seed phrase generation that let attackers drain $3.1 million

Attackers compromised Injective Labs’ repository and injected credential-stealing code into the authentic npm SDK packages used by DeFi blockchain developers.

OpenMandriva Linux caught a contributor sabotage attempt before production, disclosing the insider supply chain attack after an internal community dispute.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.