Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency. This triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging.
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads. A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency.
TrendAI™ Research at RSAC 2026: Advancing Defense Across AI‑Driven and Cyber‑Physical Threats. TrendAI™ Research explored agentic AI cybercrime and EV infrastructure security through two research sessions at RSAC 2026.
The Real Risk of Vibecoding. This blog looks at how AI‑driven vibecoding speeds up software development while increasing security risk by outpacing traditional review and ownership.
TrendAI™ Research at RSAC 2026: Advancing Defense Across AI‑Driven and Cyber‑Physical Threats. TrendAI™ Research explored agentic AI cybercrime and EV infrastructure security through two research sessions at RSAC 2026.
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads. A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency.