Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article discusses how AI agents are embedded across multiple layers of an organization, including applications, endpoints, and cloud workloads. It explains that AI attacks begin with prompt manipulation and result in harmful actions, and advocates for a unified security approach rather than fragmented tools.
This article explains how AI agents have permeated every layer of an environment, from employee apps to endpoints and cloud workloads, and that every AI attack starts as an interaction and ends as an action. SentinelOne's approach treats these surfaces as one chain, defending the agentic stack by discovering shadow AI use, governing access for non-human identities, and stopping prompt injection and jailbreaks.
This article reports on a widespread npm worm that originated from a malicious version of the keyv package ([email protected]) and spread to hundreds of other packages. The malware uses preinstall scripts to steal credentials from developer workstations and CI systems, and can also plant hooks in Claude Code and VS Code.
A credential-stealing npm worm that originated in [email protected] spread to hundreds of packages across multiple organizations on August 4, 2026. It uses preinstall scripts to harvest credentials and propagate via npm publishing access.
This article reports on a widespread npm worm that originated from a malicious version of the keyv package ([email protected]) and spread to hundreds of other packages. The malware uses preinstall scripts to steal credentials from developer workstations and CI systems, and can also plant hooks in Claude Code and VS Code.
This article from LevelBlue SpiderLabs discusses the July 2026 cyberattacks against U.S. water and wastewater systems. The organization has increased monitoring for related indicators of compromise across client environments.