TL;DR A malicious release of TensorLake's TypeScript SDK, tensorlake@0.5.144, used an install hook to search for developer credentials and accept remote commands. Sonatype's code review found that its ...
6don MSN
This popular AI agent could be hacked by a single email — with potentially disastrous consequences
Researchers found a way around Manus' guardrails and got it to execute a simple email prompt injection attack.
Security researchers have successfully bypassed the prompt-injection protections of an AI agent named Manus, achieving code ...
A group of VS Code theme extensions linked to GlassWorm, a malware campaign targeting developers. Their investigation ...
Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised ...
Hackers use public blockchains as C2 channels for supply chain malware, evading domain blocks and stealing cloud credentials.
GlassWorm hides malware in VS Code theme extensions, targeting developers through Visual Studio Marketplace and Open VSX.
A report published by Google's Threat Intelligence Group (GTIG) on September 9, 2026, details MCP server hijacking and supply ...
Police, judicial authorities, and security agencies in Japan, the U.S., and other countries have issued urgent warnings ...
Unsloth details how Studio scans model code, blocks flagged weights, inspects packages and sandboxes tools before anything ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results