Checkmarx Jenkins AST plugin compromised in TeamPCP supply chain attack
Checkmarx has confirmed that a modified version of its Jenkins AST plugin was published to the Jenkins Marketplace, extending a wider supply chain incident that…
Checkmarx has confirmed that a modified version of its Jenkins AST plugin was published to the Jenkins Marketplace, extending a wider supply chain incident that…
Magecart-style attackers are abusing Google Tag Manager to inject credit card skimmers into ecommerce websites, making malicious payment theft scripts harder for site owners and…
PHP maintainers have fixed a serious SOAP extension vulnerability that can let remote attackers execute code on vulnerable servers in some configurations. The flaw is…
A flaw in Anthropic’s Claude in Chrome extension can let a malicious Chrome extension hijack Claude’s browser agent and push it into accessing sensitive data…
A malicious Chrome extension impersonating TronLink has been used to steal crypto wallet credentials from TRON users. Security researchers at SlowMist found that the extension…
A critical vulnerability in Cline’s Kanban server can let a malicious website connect to a developer’s local AI agent session, steal workspace data, inject terminal…
North Korean threat actors are using malicious Git hooks to target software developers through fake job interviews and coding assessments. The campaign is linked to…
Hackers are abusing Microsoft Teams accounts to impersonate IT support staff and push ModeloRAT malware into corporate environments. The campaign uses a familiar workplace trust…
SAP has released its May 2026 Security Patch Day updates, fixing a critical SQL injection vulnerability in SAP S/4HANA and another critical flaw in SAP…