Two fake spellchecker packages on PyPI hid a Python RAT in dictionary files, activating malware on import in version 1.2.0.
A critical-severity vulnerability in the vm2 Node.js sandbox library, tracked as CVE-2026-22709, allows escaping the sandbox and executing arbitrary code on the underlying host system.
North Korea is doubling down on a familiar playbook by weaponizing trust in open-source software and developer workflows. The ...
A source trapped inside an industrial-scale scamming operation contacted me, determined to expose his captors’ crimes—and ...
A critical Grist-Core flaw (CVE-2026-24002, CVSS 9.1) allows remote code execution through malicious formulas when Pyodide ...
Two VSCode extensions are harvesting sensitive data and sending it to China.
This is particularly high-risk for enterprises, like financial systems or anything touching personal data, where data leakage ...
January 26, 2026: We added a new Dueling Grounds code to our list for 500 coins and 75 gems! We also removed some expired codes If you want to get yourself an advantage, you should really grab some ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results