Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour […]
In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials […]
The hacker group TeamPCP, responsible for past issues with Trivy and KICS, has now infiltrated the popular Python package litellm. They introduced two harmful versions […]
The hacking group TeamPCP, known for recently breaching Trivy and KICS, has now infiltrated a widely used Python package called litellm. They introduced two infected […]
TeamPCP, the same cybercriminals behind the Trivy supply chain attack, have compromised two more GitHub Actions workflows to steal credentials. These workflows, both from the […]
It’s yet another week proving the internet remains insecure. Systems assumed to be safe are easily compromised, highlighting a continued disregard for essential security advice. […]
Trivy, a well-known open-source tool for finding vulnerabilities supported by Aqua Security, experienced a security breach for the second time in a month, resulting in […]
Trivy, a widely used open-source vulnerability scanner from Aqua Security, experienced its second compromise in a month, resulting in the distribution of malware designed to […]
Researchers atĀ SocketĀ identified a targeted supply chain attack involving five malicious Rust crates and an autonomous AI bot designed to steal developer secrets. Malicious Rust Crates […]
© Bulletproof Servers. All rights reserved.