
Hijacked npm and Go Packages Exploit VS Code MCP to Deploy Infostealer
Hijacked npm and Go packages exploit VS Code’s MCP tasks to bypass npm lifecycle hook protections and deploy a cross-platform

Hijacked npm and Go packages exploit VS Code’s MCP tasks to bypass npm lifecycle hook protections and deploy a cross-platform

Ukraine’s SBU and the FBI jointly exposed campaigns by Russian FSB-linked UNC5792 and GRU-linked UNC4221 stealing Signal and WhatsApp backup

The US State Department’s Rewards for Justice program offers $10 million for intelligence on UNC5792 and UNC4221, Russian groups targeting

Mozilla’s 0DIN researchers show a clean GitHub repo can trick AI coding tools into running malware via DNS TXT records,

The Trump administration’s ongoing national security review now restricts OpenAI’s GPT-5.6 and Anthropic’s full model program to government-vetted customers.

The Athena coalition of about 24 companies including Docker, Cisco, and Cloudflare used AI to find 20,000+ vulnerabilities across 500

Threat actor Icarus exploited Klue’s Salesforce OAuth integration to breach CRM data at cybersecurity firms including Huntress and Recorded Future

Operation Endgame dismantled nearly 15,000 SocGholish-infected WordPress sites and 106 C2 servers linked to Russian cybercrime group Evil Corp in

ShapedPlugin’s plugin update system was compromised by attackers who pushed malicious code to paying WordPress customers through the company’s verified

Microsoft disclosed a Windows crypto clipper campaign active since February 2026, using USB LNK worm spreading and Tor-based C2 to
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.