Chainguard's new Athena coalition uses AI to fix open-source flaws - before attackers exploit them ...
Microsoft details AutoJack exploit chain targeting AutoGen Studio MCP WebSocket in pre-release builds, enabling ...
Mastra npm packages added easy-day-js malware, exposing developer systems and CI runners to infostealer risks.
CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request.
Attackers hijacked over 1,500 packages in Arch Linux's AUR to plant a credential stealer. The official repos are safe, but the trust model took the hit.