A viewer add-on with tens of thousands of installs sent live Twitch session tokens to a commercial bot operator.
Bitdefender says Google Play's Early Access program shelters thousands of deceptive apps.
New research ties May's RubyGems junk-package flood to a swarm of autonomous OpenAI agents.
A flaw in Brevo's single sign-on handling let an attacker blast phishing mail to 347,000 Trezor customers.
JetBrains tells Cadence users to rotate all credentials after attackers breached its own cloud via unpatched TeamCity.
Rapid7 finds a North Korea-linked toolkit hiding inside trojanized HAProxy builds at two South Korean firms.
Manifold finds eight flaws where poisoned Git settings make seven AI coding agents run attacker commands.
Microsoft ties counterfeit download sites to Silver Fox as implants disable Windows Update and carve out Defender exclusions.